Contactless Smartcard Digital Tag Blocks Malicious EMV Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing technologies fail to effectively prevent malicious applications from accessing and stealing sensitive information from EMV standard-based credit cards via near-field communication (NFC), leading to unauthorized transactions and security breaches.

Innovation Solution

A system and method that utilize a digital tag, specifically an Android Application Record (AAR) tag, stored on a contactless smartcard, which, when detected by a mobile device, launches a designated application to prevent unauthorized access and execution of malicious software, ensuring only authorized applications can access the card information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If NFC technology is enabled for contactless credit card transactions, then transaction convenience is improved, but security vulnerability to malicious software increases

Engineering Contradiction:
Improvetransaction convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by launching an authorized application in response to detecting an NFC field before malicious software can intercept card information. The authorized application is pre-configured to handle NFC communications, and its automatic launch prevents malicious software from accessing sensitive data first

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authorized application serves as an intermediary between the NFC field detection and the card information access. It mediates the communication by establishing a secure channel through which only authorized transactions can occur, blocking direct access by malicious software

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If malicious software is installed on a mobile device, then unauthorized access to card information becomes possible, but user awareness and control are reduced

Engineering Contradiction:
Improveunauthorized access capabilityVSAvoiduser control
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system applies preliminary anti-action by having the authorized application launch automatically when an NFC field is detected, creating a protective barrier before malicious software can execute its unauthorized access. This preemptive measure counteracts the harmful effect of installed malicious software

Inventive Principle:
Principle #9Preliminary anti-action

3Speed

If the mobile device automatically reads card information whenever in NFC range, then transaction speed is improved, but data security is compromised

Engineering Contradiction:
Improvetransaction speedVSAvoiddata security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system implements dynamics by making the information reading process conditional rather than automatic. The authorized application dynamically controls when card information is read based on authentication status and transaction validity, rather than continuously reading whenever in NFC range

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240169344A1System, method, and computer-accessible medium for blocking malicious EMV transactions
Publication Date: 2024.05.23 CAPITAL ONE SERVICES LLC
  • US20240169344A1 patent drawing
  • US20240169344A1 patent drawing
  • US20240169344A1 patent drawing

AI summary

An exemplary system, method, and computer-accessible medium can include, for example, storing on a first device an applet configured to generate a digital tag; receiving a request at the first device for information; configuring the digital tag to be associated with at least one of (i) an application or (ii) an input on a second device, such that receipt of the digital tag by a second device causes the application to launch on the second device; and emitting from the first device a digital tag.