NFC Contactless Card Authentication with Server-Verified Cryptograms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing contactless cards face challenges in data security, authentication, and verification, with methods like email and SMS being vulnerable to attacks, and chip-based cards relying on insecure login credentials.

Innovation Solution

A system and method for cryptographic authentication of contactless cards using a contactless card with a processor and memory, communicating with a client device and authentication server, generating and verifying cryptograms for secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication methods (email, SMS, login credentials) are used, then ease of operation is improved, but data security and reliability deteriorate due to vulnerabilities to attacks and hacking

Engineering Contradiction:
Improveease of authenticationVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces traditional mechanical authentication mechanisms (email, SMS, login credentials) with a contactless card-based authentication system using NFC technology. The card contains a processor and memory that generate cryptographic responses, substituting the vulnerable communication-based authentication with a secure hardware-based solution that eliminates the need for passwords and communication protocols susceptible to hacking.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The contactless card acts as an intermediary between the user and the authentication server. Instead of directly exposing login credentials or communication data, the card generates cryptographic responses (cryptograms) that verify identity without transmitting sensitive information over the network, thereby securing the authentication process while maintaining ease of use.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If chip-based cards with log-in credentials are used, then data security is improved over magnetic strip cards, but reliability deteriorates when credentials are compromised

Engineering Contradiction:
Improvedata securityVSAvoidcredential compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and eliminates the vulnerable login credential component from the authentication system. Instead of relying on stored credentials that can be compromised, the system uses a contactless card with a processor that generates cryptographic responses on-demand, removing the harmful credential storage and transmission环节 entirely.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the fundamental parameter of authentication from static credentials (passwords, card numbers) to dynamic cryptographic responses. Each authentication attempt generates a unique cryptogram based on challenges from the authentication server, making the authentication state changeable and不可预测, thereby eliminating the risk of credential compromise.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If contactless cards with cryptographic authentication are implemented, then data security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication functionality directly into the contactless card itself by integrating a processor and memory with cryptographic capabilities. This consolidation eliminates the need for separate authentication devices or complex server-based authentication systems, reducing overall system complexity while maintaining high security standards.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The contactless card performs self-authentication by containing its own processor and memory that can generate cryptographic responses independently. The card serves its own authentication needs without requiring external authentication devices or complex system infrastructure, thereby simplifying the overall system while improving security.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances data security and authentication by reducing vulnerabilities in contactless card transactions through multi-factor authentication.

Implementation Method 1

a cryptogram generated by placing the contactless card in a communication field of the client device

Methodology Applied
Scientific EffectElectromagnetic induction: Electromagnetic Induction

Data Source

PatentUS20250307803A1Systems and methods for cryptographic authentication of contactless cards
Publication Date: 2025.10.02 CAPITAL ONE SERVICES LLC
  • US20250307803A1 patent drawing
  • US20250307803A1 patent drawing
  • US20250307803A1 patent drawing

AI summary

Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key. Example embodiments of systems and methods can be used to provide further authentication and added levels of security for transactions.