Systems and methods for authorization and access to services using contactless cards

US11182785B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11182785-B2
Application numberUS-201916659189-A
CountryUS
Kind codeB2
Filing dateOct 21, 2019
Priority dateOct 2, 2018
Publication dateNov 23, 2021
Grant dateNov 23, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.

First claim

Opening claim text (preview).

What is claimed is: 1. An authorization system, comprising: a contactless card having a processor and a memory, the memory of the contactless card containing a card key and transmission data; an application comprising instructions for execution on a receiving device having a processor and a memory, the memory of the receiving device containing an application key; wherein the contactless card is configured to: encrypt the transmission data using one or more cryptographic algorithms and the card key to yield encrypted transmission data, and transmit the encrypted transmission data to the application; wherein the application is configured to decrypt the encrypted transmission data using the one or more cryptographic algorithms and the application key; wherein the application is configured to authenticate a user identity associated with a user prior to performing one or more actions relating to the user; and wherein the user identity is associated with at least one selected from the group of a rank, a category, and a points system so as to provide access to an agent with at least one enhanced authorization. 2. The authorization system of claim 1 , wherein: the association of the user's identity with at least one selected from the group of a rank, a category, and a points system entitles the user at least one benefit, and the at least one benefit comprises at least one selected from the group of faster access to the agent, a certain experience level for the agent, and a certain quality rating for the agent. 3. The authorization system of claim 1 , wherein, after authentication of the user identity, the application is configured to allow the agent access to user information. 4. The authorization system of claim 1 , wherein the at least one enhanced authorization includes at least one selected from the group of an authorization to refund or waive charges, an authorization to renew or modify a contract, an authorization to provide free or reduced shipping, and an authorization to provide additional services. 5. The authorization system of claim 1 , wherein the application is configured to route one or more calls based on a transaction history after receiving the authenticated user identity. 6. The authorization system of claim 1 , wherein the application is configured to record information related to user identity authentication behavior. 7. The authorization system of claim 6 , wherein the recorded information related to user identity authentication behavior comprises at least one selected from the group of time of authentication, location of authentication, type of contactless card, type of receiving device, movement of one or more entries into a communication field, and timing of one or more entries into a communication field. 8. The authorization system of claim 6 , wherein a user behavior profile is created based on the recorded information related to user identity authentication behavior. 9. The authorization system of claim 8 , wherein the user behavior profile is configured to detect one or more indicators of fraud. 10. The authorization system of claim 9 , wherein at least one indicator selected from the one or more indicators includes a determination of a predetermined threshold of variation so as to identify the fraud. 11. The authorization system of claim 3 , wherein, after authentication of the user identity, the application is configured to transmit insurance data to the agent. 12. A method of secure communication using a contactless card comprising a processor and a memory, the memory of the contactless card containing a card key and transmission data, the method comprising the steps of: encrypting, by the contactless card, the transmission data using one or more cryptographic algorithms and the diversified key to yield encrypted transmission data; transmitting, by the contactless card, the encrypted transmission data to an application, the application comprising instructions for execution on a receiving device comprising a processor and a memory, the memory of the receiving device storing an application key; decrypting, by the application, the encrypted transmission data using the one or more cryptographic algorithms and the application key; authenticating, by the application, a user identity associated with a user prior to performing one or more actions relating to the user, wherein the user identity is associated with at least one selected from the group of a rank, a category, and a points system so as to provide access to an agent with at least one enhanced authorization; and providing, by the application, access to an agent with the at least one enhanced authorization. 13. The method of claim 12 , wherein the at least one enhanced authorization includes at least one selected from the group of an authorization to refund or waive charges, an authorization to renew or modify a contract, an authorization to provide free or reduced shipping, and an authorization to provide additional services. 14. The method of claim 12 , further comprising routing, by the application, one or more calls based on a transaction history after receiving the authenticated user identity. 15. The method of claim 14 , wherein the one or more calls are routed to a vocalized chat agent. 16. The method of claim 12 , further comprising recording, by the application, information related to user identity authentication behavior. 17. The method of claim 16 , wherein the recorded information related to user identity authentication behavior comprises at least one selected from the group of time of authentication, location of authentication, type of contactless card, type of receiving device, movement of one or more entries into a communication field, and timing of one or more entries into a communication field. 18. The method of claim 16 , wherein a user behavior profile is created based on the recorded information related to user identity authentication behavior. 19. The method of claim 18 , wherein the user behavior profile is configured to detect one or more indicators of fraud. 20. An authorization system, comprising: a mobile device comprising a processor, a communication interface and a memory, the memory of the mobile device storing an application key and an application comprising instructions for execution on the mobile device and the communication interface configured to generate a communication field; and a contactless card having a processor and memory, the memory of the contactless card containing a card key and transmission data; wherein the contactless card is configured to, after entry in to the communication field: encrypt the transmission data using one or more cryptographic algorithms and the card key to yield encrypted transmission data, and transmit the encrypted transmission data to the application via the communication field; and wherein the application is configured to: decrypt the encrypted transmission data using the one or more cryptographic algorithms and the application key; and authenticate a user identity associated with a user prior to performing one or more actions relating to the user, wherein the user identity is associated with at least one selected from the group of a rank, a category, and a points system so as to provide access to an agent with at least one enhanced authorization.

Assignees

Inventors

Classifications

  • Key agreement, i.e. key establishment technique in which a shared key is derived by parties as a function of information contributed by, or associated with, each of these (network architectures or network communication protocols for key exchange in a packet data network H04L63/061) · CPC title

  • H04L9/002Primary

    Countermeasures against attacks on cryptographic mechanisms (network architectures or network communication protocols for protection against malicious traffic H04L63/1441) · CPC title

  • Use of certificates or encrypted proofs of transaction rights · CPC title

  • Modes of operation, e.g. cipher block chaining [CBC], electronic codebook [ECB] or Galois/counter mode [GCM] · CPC title

  • Payment applications installed on the mobile devices · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11182785B2 cover?
Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can ge…
Who is the assignee on this patent?
Capital One Services Llc
What technology area does this patent fall under?
Primary CPC classification H04L9/002. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 23 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).