NFC Card Authentication Using Dynamic Data Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for activating financial cards and authenticating account access are time-consuming and insecure, relying on log-in credentials that can be compromised, lacking robust multi-factor authentication.
Innovation Solution
The system employs a contactless device, such as an RFID card, using near field communication (NFC) for a bi-directional authentication protocol between the card and a user's computing device, incorporating offline dynamic data authentication to verify user identity and card ownership, enabling multifactor authentication for secure account access and card activation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If log-in credentials (username and password) are used for account access, then ease of operation is improved, but reliability is worsened because credentials can be compromised
Solution Approach 1:
The authentication system is segmented into multiple independent factors: something the user knows (credentials), something the user has (contactless card), and something the user is (biometric data). This segmentation ensures that compromise of one factor does not lead to complete system failure, thereby improving reliability while maintaining ease of operation through the primary credential method.
Solution Approach 2:
The system performs preliminary authentication actions by verifying credentials first, then optionally requiring additional verification through contactless card or biometric factors. This preliminary action structure allows most users to access quickly with simple credentials while providing enhanced security layers for sensitive operations, balancing ease of operation with reliability.
2Reliability
If card activation requires calling a telephone number or visiting a website, then reliability is improved by verifying identity, but loss of time increases due to the time-consuming process
Solution Approach 1:
The card activation process is transformed into a self-service operation where the cardholder uses their own contactless card and computing device to complete activation. The system automatically verifies identity through the authentication protocol without requiring customer service intervention, thereby maintaining reliability while eliminating the time loss associated with manual verification processes.
Solution Approach 2:
The manual activation process (calling telephone numbers or visiting websites with manual verification) is replaced by an automated electronic authentication system using NFC technology. This substitution eliminates the need for human agent intervention and manual data entry, significantly reducing activation time while maintaining or improving verification reliability through cryptographic protocols.
3Device complexity
If static data check methods are used for NFC authentication, then device complexity is reduced, but reliability is worsened due to lack of security compared to dynamic data authentication
Solution Approach 1:
The authentication system transitions from static data checks to dynamic data authentication where cryptographic keys and challenge-response protocols generate unique authentication data for each transaction. This dynamic approach prevents replay attacks and ensures that each authentication event is secure, improving reliability while the implementation details are managed within the NFC protocol to minimize perceived device complexity.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach provides a secure and efficient method for authenticating cardholders, reducing the risk of unauthorized access by utilizing NFC for dynamic data verification, ensuring the card is linked to the correct user account, and enabling both first and second-level account access securely.
Implementation Method 1
A contactless device (e.g., card, tag, transaction card or the like) may use near field communications technology for bi-directional or uni-directional contactless short-range communications based on, for example, radio frequency identification (RFID) standards
Implementation Method 2
near field communications technology for bi-directional or uni-directional contactless short-range communications based on, for example, radio frequency identification (RFID) standards
Data Source
AI summary
A method including receiving a first application user credential associated with a user profile; comparing, for a first match, the first application user credential with a stored second application user credential, wherein the stored second application user credential is associated with a user identity; and responsive to finding a first match, verifying the user identity by performing the following: communicating with a card using near field communication; receiving a public key of a key pair of the card and cardholder identification information of an account holder of the card; instructing the card to generate a digital signature; receiving the digital signature from the card; verifying the digital signature using the public key; and comparing, for a second match, at least a portion of the user identity with at least a portion of the cardholder identification information.


