Gesture-Based Contactless Card Authentication With Encrypted Payloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing contactless cards face challenges in data security, authentication, and activation processes, which are vulnerable to hacking and require cumbersome manual verification methods.

Innovation Solution

Implementing a contactless card with a processor and memory that dynamically generates an encrypted payload, transmitted via gestures to a client device, where servers decrypt and grant access to services based on decryption status, enhancing authentication and activation efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional email or SMS methods are used for transaction verification, then communication is simple and direct, but security is compromised due to vulnerability to hacking and unauthorized access

Engineering Contradiction:
Improvetransaction securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cryptographic intermediary layer between the contactless card and the verification system. Instead of directly using email or SMS, the system uses encrypted payloads with digital signatures and cryptographic keys as intermediaries to transfer authentication information securely through the client application, eliminating direct vulnerability to email/SMS hacking

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical communication methods (email, SMS) with cryptographic mechanisms. The authentication process substitutes text-based communication with cryptographic operations including payload encryption, digital signing, and key-based verification, which are fundamentally more secure against unauthorized access

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If card activation requires manual verification through telephone or website, then security can be verified, but the process is time-consuming and complex

Engineering Contradiction:
Improvecard activation speedVSAvoidactivation process simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The contactless card performs self-activation by automatically generating and transmitting its own encrypted payload through gesture-based communication with the client application. The card autonomously completes authentication without requiring the user to manually call or visit websites, achieving both speed and simplicity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cryptographic authentication data is pre-configured in the contactless card during manufacturing. This preliminary setup enables the card to immediately perform secure authentication and self-activation without requiring subsequent manual verification steps, thus accelerating the activation process while maintaining security

Inventive Principle:
Principle #10Preliminary action

3Reliability

If log-in credentials are used for account access, then authentication can be performed, but security is compromised when credentials are compromised

Engineering Contradiction:
Improveaccount access securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication credentials from the traditional log-in process and embeds them directly within the contactless card's encrypted payload. This separation removes the vulnerability of transmitting credentials through vulnerable channels like email or SMS, as the authentication data remains securely confined within the card's cryptographic system

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements dynamic cryptographic authentication where the contactless card generates and transmits encrypted payloads with digital signatures that change with each authentication attempt. This dynamic approach replaces static log-in credentials with continuously changing cryptographic proofs, preventing credential compromise and replay attacks

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12526149B2Systems and methods for cryptographic authentication of contactless cards
Publication Date: 2026.01.13 CAPITAL ONE SERVICES LLC
  • US12526149B2 patent drawing
  • US12526149B2 patent drawing
  • US12526149B2 patent drawing

AI summary

Example embodiments of systems and methods for data transmission between a contactless card, a client device, and one or more servers are provided. One or more applets of the contactless card are configured to dynamically generate an encrypted payload appended to a link, wherein the contactless card is configured to transmit the link with the appended payload to the client device via one or more gestures. The one or more servers are configured to receive the payload from the client device via one or more applications, parse and decrypt the payload after launch of one or more applications, and transmit one or more notifications to the client device based on a status associated with decryption of the payload. The client device is granted access to a plurality of services associated with the one or more servers based on the one or more notifications received from the one or more servers.