Preemptive Passcode Generation for Contactless Card Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for user devices are vulnerable to attacks, such as man-in-the-middle attacks, which can intercept public keys or authentication data, and additional security measures can be overly restrictive for legitimate users, especially in scenarios like traveling where users may not have access to their contactless cards or compatible networks.

Innovation Solution

A method that generates preemptive passcodes based on cryptograms from contactless cards, allowing users to authorize operations without re-detectoring the card, using a server to store and validate these passcodes, which can be used up to a maximum number of times or within a time window, providing an additional layer of authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional security measures are implemented to prevent attackers from intercepting authentication data, then security is improved, but the measures become overly restrictive for legitimate users

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system generates and stores passcodes in advance before authentication is needed. When a user initiates authentication, the pre-generated passcode is immediately available for verification without requiring real-time card detection or network communication, thus maintaining security while improving user convenience

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary passcode mechanism that bridges the gap between security requirements and user convenience. The passcode serves as a mediator that can be verified without requiring the user to have physical access to the contactless card or be connected to a compatible network at the moment of authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time card detection is required for authentication, then security against fraudulent activity is improved, but the system becomes unusable when users are not physically present with the card

Engineering Contradiction:
Improvesecurity against fraudVSAvoidflexibility of authentication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Passcodes are generated and stored in advance when the user has access to the contactless card. This preliminary action allows the authentication system to function even when the user is later unable to physically present the card, such as when traveling or away from compatible devices

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of the authentication credential in the form of a passcode that can be stored and transmitted through alternative channels. This copy enables authentication without requiring the original card to be physically present during the authentication process

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250103688A1Verification operations based on wireless communication
Publication Date: 2025.03.27 CAPITAL ONE SERVICES LLC
  • US20250103688A1 patent drawing
  • US20250103688A1 patent drawing
  • US20250103688A1 patent drawing

AI summary

Verification techniques based on wireless communication with a contactless card. A passcode is generated based on a cryptogram read from a contactless card. The passcode is generated responsive to a device detecting the contactless card. The passcode has an associated account and an associated validity criterion. The passcode is stored on a server. A request specifying to perform an operation associated with the account and further specifying a passcode generated prior to the operation being specified is received. Upon a determination that the specified passcode matches the stored passcode and that the validity criterion remains satisfied, the operation specified by the request is authorized to be performed. The operation is authorized without requiring the device to redetect the contactless card