Gesture-Based Contactless Card Authentication With Encrypted Payloads
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless cards face challenges in data security, authentication, and activation processes, which are vulnerable to hacking and require cumbersome manual verification methods.
Innovation Solution
Implementing a contactless card with a processor and memory that dynamically generates an encrypted payload, transmitted via gestures to a client device, where servers decrypt and grant access to services based on decryption status, enhancing authentication and activation efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional email or SMS methods are used for transaction verification, then communication is simple and direct, but security is compromised due to vulnerability to hacking and unauthorized access
Solution Approach 1:
The patent introduces a cryptographic intermediary layer between the contactless card and the verification system. Instead of directly using email or SMS, the system uses encrypted payloads with digital signatures and cryptographic keys as intermediaries to transfer authentication information securely through the client application, eliminating direct vulnerability to email/SMS hacking
Solution Approach 2:
The patent replaces traditional mechanical communication methods (email, SMS) with cryptographic mechanisms. The authentication process substitutes text-based communication with cryptographic operations including payload encryption, digital signing, and key-based verification, which are fundamentally more secure against unauthorized access
2Productivity
If card activation requires manual verification through telephone or website, then security can be verified, but the process is time-consuming and complex
Solution Approach 1:
The contactless card performs self-activation by automatically generating and transmitting its own encrypted payload through gesture-based communication with the client application. The card autonomously completes authentication without requiring the user to manually call or visit websites, achieving both speed and simplicity
Solution Approach 2:
The cryptographic authentication data is pre-configured in the contactless card during manufacturing. This preliminary setup enables the card to immediately perform secure authentication and self-activation without requiring subsequent manual verification steps, thus accelerating the activation process while maintaining security
3Reliability
If log-in credentials are used for account access, then authentication can be performed, but security is compromised when credentials are compromised
Solution Approach 1:
The patent extracts the authentication credentials from the traditional log-in process and embeds them directly within the contactless card's encrypted payload. This separation removes the vulnerability of transmitting credentials through vulnerable channels like email or SMS, as the authentication data remains securely confined within the card's cryptographic system
Solution Approach 2:
The patent implements dynamic cryptographic authentication where the contactless card generates and transmits encrypted payloads with digital signatures that change with each authentication attempt. This dynamic approach replaces static log-in credentials with continuously changing cryptographic proofs, preventing credential compromise and replay attacks
Data Source
AI summary
Example embodiments of systems and methods for data transmission between a contactless card, a client device, and one or more servers are provided. One or more applets of the contactless card are configured to dynamically generate an encrypted payload appended to a link, wherein the contactless card is configured to transmit the link with the appended payload to the client device via one or more gestures. The one or more servers are configured to receive the payload from the client device via one or more applications, parse and decrypt the payload after launch of one or more applications, and transmit one or more notifications to the client device based on a status associated with decryption of the payload. The client device is granted access to a plurality of services associated with the one or more servers based on the one or more notifications received from the one or more servers.


