NFC Card Authentication Using Dynamic Data Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for activating financial cards and authenticating account access are time-consuming and insecure, relying on log-in credentials that can be compromised, lacking robust multi-factor authentication.

Innovation Solution

The system employs a contactless device, such as an RFID card, using near field communication (NFC) for a bi-directional authentication protocol between the card and a user's computing device, incorporating offline dynamic data authentication to verify user identity and card ownership, enabling multifactor authentication for secure account access and card activation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If log-in credentials (username and password) are used for account access, then ease of operation is improved, but reliability is worsened because credentials can be compromised

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent factors: something the user knows (credentials), something the user has (contactless card), and something the user is (biometric data). This segmentation ensures that compromise of one factor does not lead to complete system failure, thereby improving reliability while maintaining ease of operation through the primary credential method.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication actions by verifying credentials first, then optionally requiring additional verification through contactless card or biometric factors. This preliminary action structure allows most users to access quickly with simple credentials while providing enhanced security layers for sensitive operations, balancing ease of operation with reliability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If card activation requires calling a telephone number or visiting a website, then reliability is improved by verifying identity, but loss of time increases due to the time-consuming process

Engineering Contradiction:
ImprovereliabilityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The card activation process is transformed into a self-service operation where the cardholder uses their own contactless card and computing device to complete activation. The system automatically verifies identity through the authentication protocol without requiring customer service intervention, thereby maintaining reliability while eliminating the time loss associated with manual verification processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual activation process (calling telephone numbers or visiting websites with manual verification) is replaced by an automated electronic authentication system using NFC technology. This substitution eliminates the need for human agent intervention and manual data entry, significantly reducing activation time while maintaining or improving verification reliability through cryptographic protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If static data check methods are used for NFC authentication, then device complexity is reduced, but reliability is worsened due to lack of security compared to dynamic data authentication

Engineering Contradiction:
Improvedevice complexityVSAvoidreliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The authentication system transitions from static data checks to dynamic data authentication where cryptographic keys and challenge-response protocols generate unique authentication data for each transaction. This dynamic approach prevents replay attacks and ensures that each authentication event is secure, improving reliability while the implementation details are managed within the NFC protocol to minimize perceived device complexity.

Inventive Principle:
Principle #15Dynamics

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach provides a secure and efficient method for authenticating cardholders, reducing the risk of unauthorized access by utilizing NFC for dynamic data verification, ensuring the card is linked to the correct user account, and enabling both first and second-level account access securely.

Implementation Method 1

A contactless device (e.g., card, tag, transaction card or the like) may use near field communications technology for bi-directional or uni-directional contactless short-range communications based on, for example, radio frequency identification (RFID) standards

Methodology Applied
Scientific EffectNear field communication (NFC): Electromagnetic Induction

Implementation Method 2

near field communications technology for bi-directional or uni-directional contactless short-range communications based on, for example, radio frequency identification (RFID) standards

Methodology Applied
Scientific EffectRadio frequency identification (RFID): Electromagnetic Induction

Data Source

PatentUS10395244B1Systems and methods for providing card interactions
Publication Date: 2019.08.27 CAPITAL ONE SERVICES LLC
  • US10395244B1 patent drawing
  • US10395244B1 patent drawing
  • US10395244B1 patent drawing

AI summary

A method including receiving a first application user credential associated with a user profile; comparing, for a first match, the first application user credential with a stored second application user credential, wherein the stored second application user credential is associated with a user identity; and responsive to finding a first match, verifying the user identity by performing the following: communicating with a card using near field communication; receiving a public key of a key pair of the card and cardholder identification information of an account holder of the card; instructing the card to generate a digital signature; receiving the digital signature from the card; verifying the digital signature using the public key; and comparing, for a second match, at least a portion of the user identity with at least a portion of the cardholder identification information.