Systems and methods for signaling an attack on contactless cards
US-12081582-B2 · Sep 3, 2024 · US
US2017195319A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2017195319-A1 |
| Application number | US-201514983823-A |
| Country | US |
| Kind code | A1 |
| Filing date | Dec 30, 2015 |
| Priority date | Dec 30, 2015 |
| Publication date | Jul 6, 2017 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A one-time passcode authentication system includes an application server, an authentication server, and an access device, wherein the access includes an authentication engine configured to receive an authentication request from the authentication server and automatically, or in response to a single user input, initiate an access request to the application server, wherein the access request includes a token extracted from the authentication request, and the application server is configured to receive the access request, query the authentication server to authenticate the token, and enable access to an application if the token is authenticated.
Opening claim text (preview).
What is claimed is: 1 . A one-time passcode authentication system comprising: an application server, an authentication server, and an access device; the access device comprising an authentication engine; wherein the authentication engine comprises a first computer processor and a first non-transitory computer-readable medium having a first computer-executable program embedded thereon, the first computer-executable program being configured to receive an authentication request from the authentication server and initiate an access request to the application server in response to the authentication request, wherein the access request comprises a token extracted from the authentication request; and the application server comprises a second computer processor and a second non-transitory computer-readable medium having a second computer-executable program embedded thereon, the second computer-executable program being configured to receive the access request, query the authentication server to authenticate the token, and enable access to an application if the token is authenticated. 2 . The system of claim 1 , wherein the authentication server comprises an authentication data generation component configured to receive an authentication data set from the application server and generate the authentication request based on the authentication data set, such that the authentication request comprises one or more parameters extracted from the authentication data set and the token. 3 . The system of claim 2 , wherein the authentication data comprises an electronic address that uniquely identifies the access device or a user. 4 . The system of claim 3 , wherein the electronic address that uniquely identifies the access device or a user comprises a phone number, an IP address, or an email address. 5 . The system of claim 2 , wherein the authentication data generation component is further configured to encrypt the authentication request and the first computer-executable program is further configured to decrypt the authentication request. 6 . The system of claim 1 , wherein the first computer-executable program is further configured to encrypt the access request, and the second computer-executable program is further configured to decrypt the access request. 7 . The system of claim 1 , wherein the access device further comprises a device user interface component, and the first computer-executable program is further configured to cause the device user interface component to display a prompt, responsive to the authentication request, querying a user to accept the authentication request. 8 . The system of claim 7 , wherein the first computer-executable program is further configured to receive an input message from the device user interface component and initiate the access request to the application server only if the input message indicates that the user accepted the authentication request. 9 . The system of claim 7 , wherein the device user interface component comprises a biometric input device, and the input message comprises a biometric identification. 10 . The system of claim 9 , wherein the biometric input device comprises a fingerprint scanner or a retinal scanner. 11 . A computer implemented one-time passcode authentication method comprising: receiving, with an authentication server, a request data set comprising an authentication request and an identification parameter, wherein the access device identification parameter uniquely identifies the access device or a user; generating, with the authentication server, a token and an authentication data set based on the request data; receiving, with the access device, the authentication data set from the authentication server; and initiating, with the access device, an access request to an application server responsive to receiving the authentication data set, wherein the access request comprises the token. 12 . The method of claim 11 , further comprising querying the authentication server to authenticate the token, responsive to receiving the access request. 13 . The method of claim 12 , further comprising enabling, with the application server, access to an application if the token is authenticated. 14 . The method of claim 11 , wherein the identification parameter comprises a phone number, an IP address, or an email address. 15 . The method of claim 11 , further comprising encrypting the authentication data set. 16 . The method of claim 15 , further comprising encrypting the access request. 17 . The method of claim 11 , further comprising displaying, with a user interface configured on the access device, an authentication prompt responsive to receiving the authentication data set. 18 . The method of claim 17 , further comprising receiving, with the user interface, an input message from the user responsive to the authentication prompt and initiating the access request to the application server only if the input message indicates that the user accepted the authentication prompt. 19 . The method of claim 17 , further comprising receiving, with a biometric input device, a biometric input message from the user responsive to the authentication prompt and initiating the access request to the application server only if the biometric input message authenticates the user. 20 . The method of claim 19 , wherein the receiving the biometric input message comprises receiving a fingerprint scan or receiving a retinal scan.
Authentication · CPC title
wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title
Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists · CPC title
using cards, e.g. integrated circuit [IC] cards or magnetic cards · CPC title
using one-time-passwords · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.