Systems and methods for performing transactions with contactless cards
US-11182784-B2 · Nov 23, 2021 · US
US2022036349A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2022036349-A1 |
| Application number | US-202117501884-A |
| Country | US |
| Kind code | A1 |
| Filing date | Oct 14, 2021 |
| Priority date | Oct 2, 2018 |
| Publication date | Feb 3, 2022 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.
Opening claim text (preview).
1 - 40 . (canceled) 41 . A system, comprising: a contactless card having a processor and memory, the memory of the contactless card containing a card key and transmission data; an application comprising instructions for execution on a receiving device having a processor and memory, the memory of the receiving device containing an application key; wherein the contactless card is configured to: encrypt the transmission data using a cryptographic algorithm and the card key to yield encrypted transmission data, and transmit the encrypted transmission data to the application; and wherein the application is configured to: decrypt the encrypted transmission data using the cryptographic algorithm and the application key; authenticate a user identity associated with a user; and after authenticating the user identity, access sensitive information. 42 . The system of claim 41 , wherein the sensitive information comprises at least one selected from the group of academic information, financial information, and medical information. 43 . The system of claim 41 , wherein: the sensitive information comprises insurance information, and the application is further configured to transmit the insurance information to a device associated with medical provider. 44 . The system of claim 41 , wherein the application is further configured to, after authenticating the user identity and prior to accessing sensitive information, transmit a one-time passcode to a second device associated with the user. 45 . The system of claim 44 , wherein the one-time passcode is time-limited. 46 . The system of claim 41 , wherein: the receiving device comprises a server, and the contactless card is configured to transmit the encrypted transmission data to the application via one or more intermediary devices. 47 . The system of claim 41 , wherein the application is further configured to record information comprising at least one selected from the group of time of authentication, location of authentication, type of contactless card, type of receiving device, movement of one or more entries into a communication field, and timing of one or more entries into a communication field. 48 . The system of claim 47 , wherein the application is further configured to: analyze the recorded information, and generate a user behavior profile. 49 . The system of claim 48 , wherein: the application is further configured to: determine a threshold of variation for the user behavior profile, and the application is further configured to detect an indicator of fraud based on the user behavior profile, and the indicator of fraud includes behavior outside of the user behavior profile and beyond the threshold of variation. 50 . A method, comprising: encrypting, by a contactless card comprising a processor and a memory, the memory of the contactless card containing a card key and transmission data the transmission data using a cryptographic algorithm and the card key to yield encrypted transmission data, and transmitting, by the contactless card, the encrypted transmission data to an application comprising instructions for execution on a receiving device having a processor and memory, the memory of the receiving device containing an application key; decrypting, by the application, the encrypted transmission data using the cryptographic algorithm and the application key; authenticating, by the application, a user identity associated with a user; and accessing, by the application after authenticating the user identity, sensitive information. 51 . The method of claim 50 , further comprising recording, by the application, information comprising at least one selected from the group of time of authentication, location of authentication, type of contactless card, type of receiving device, movement of one or more entries into a communication field, and timing of one or more entries into a communication field. 52 . The method of claim 51 , further comprising: analyzing, by the application, the recorded information; and generating, by the application, a user behavior profile. 53 . The method of claim 52 , further comprising: determining, by the application, a threshold of variation for the user behavior profile; and detecting, by the application, an indicator of fraud based on the user behavior profile. 54 . The method of claim 53 , wherein the indicator of fraud includes behavior outside of the user behavior profile and beyond the threshold of variation. 55 . The method of the claim 50 , wherein: the sensitive information comprises financial information relating to an asset, and the method further comprises, by the application, at least one selected from the group of buying the asset, selling the asset, and transferring the asset. 56 . The method of claim 50 , wherein the method further comprises destroying, by the application, the sensitive application. 57 . A non-transitory computer-readable medium containing instructions for execution by the processor, wherein, upon execution by the processor, the instructions configure the processor to perform procedures comprising: receiving, from a contactless card, encrypted transmission data; decrypting, using a cryptographic algorithm and an application key, the transmission data; authenticating a user identity associated with the user; and after authenticating the user identity, accessing sensitive information. 58 . The non-transitory computer-readable medium of claim 57 , wherein the sensitive information comprises at least one selected from the group of academic information, financial information, and medical information. 59 . The non-transitory computer-readable medium of claim 57 , wherein the procedures further comprise, after authenticating the user identity and prior to accessing sensitive information, transmitting, by the application, a one-time passcode to a smartphone associated with the user. 60 . The non-transitory computer-readable medium of claim 57 , wherein the procedures further comprise modifying the sensitive information.
Contactless payments by cards · CPC title
Financial cryptography, e.g. electronic payment or e-cash · CPC title
Modes of operation, e.g. cipher block chaining [CBC], electronic codebook [ECB] or Galois/counter mode [GCM] · CPC title
involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token (network architectures or network communication protocols for supporting authentication of entities using an additional device in a packet data network H04L63/0853) · CPC title
using additional device, e.g. trusted platform module [TPM], smartcard, USB or hardware security module [HSM] · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.