Contactless Magnetic Stripe Card Key Diversification for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless legacy magnetic stripe cards lack secure data transmission and user authentication mechanisms, making them vulnerable to unauthorized transactions and data breaches when interacting with client devices like smartphones.
Innovation Solution
Integrating a contactless legacy magnetic stripe card with processing circuitry and NFC technology, enabling secure data transmission and user authentication by generating diversified keys using a master key, counter value, and cryptographic algorithms, and utilizing client devices like smartphones for encrypted data relay to backend servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If contactless legacy magnetic stripe cards are used for transactions, then compatibility with existing merchant systems is maintained, but data security and transaction integrity are compromised
Solution Approach 1:
The patent introduces a mobile device as an intermediary between the legacy magnetic stripe card and the merchant terminal. The mobile device runs a wallet application that captures data from the card's magnetic stripe and performs cryptographic operations to secure the transaction data before transmitting it to the merchant terminal, thus bridging the security gap between legacy cards and modern security requirements
Solution Approach 2:
The patent replaces the traditional mechanical swiping action with a contactless NFC-based transmission system. The mobile device uses NFC technology to wirelessly transmit encrypted transaction data to the merchant terminal, eliminating the need for physical contact and providing enhanced security through cryptographic encryption while maintaining compatibility with existing terminal infrastructure
2Reliability
If cryptographic key diversification is implemented, then data security is enhanced, but device complexity increases
Solution Approach 1:
The patent divides the cryptographic key into multiple components: a static master key stored in the mobile device and a dynamic counter value that changes with each transaction. This segmentation allows the system to generate diverse encryption keys through simple combination of these components without requiring complex cryptographic hardware or processing
Solution Approach 2:
The patent uses parameter changes by incrementing a counter value with each transaction to generate different encryption keys. This simple parameter modification (incrementing a counter) achieves key diversification and prevents replay attacks without requiring complex cryptographic algorithms or processing, thus enhancing security while maintaining low device complexity
3Reliability
If contactless authentication is added to legacy cards, then user authentication is improved, but the card structure becomes more complex
Solution Approach 1:
The patent uses the mobile device as an intermediary that provides authentication functionality without modifying the card itself. The wallet application in the mobile device captures data from the card's magnetic stripe and performs authentication operations, keeping the card structure simple while adding robust user authentication through biometric verification and cryptographic processing in the mobile device
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances transaction security and user authentication for contactless legacy magnetic stripe cards by ensuring secure data exchange and authorization, reducing the risk of unauthorized access and data breaches.
Implementation Method 1
Integrating a contactless legacy magnetic stripe card with processing circuitry and NFC technology
Data Source
AI summary
A technique for generating a diversified encryption key for a contactless legacy magnetic stripe card is disclosed. The diversified key can be generated using a master key, a key diversification value and an encryption algorithm. In one example embodiment, the key diversification value can be provided by the user as a fingerprint, numeric code or photo. The user can provide the key diversification value to the card or a cellphone. The card can generate the diversified key using the user provided key diversification value. The card or the cellphone can transmit the user provided diversification value to the server and the server can regenerate the diversified key using the user provided diversification value.


