Systems and methods to provide contactless cards for transactions

US2025005555A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2025005555-A1
Application numberUS-202418759533-A
CountryUS
Kind codeA1
Filing dateJun 28, 2024
Priority dateJun 30, 2023
Publication dateJan 2, 2025
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods to provide contactless cards for transactions are disclosed. In an exemplary transaction provisioning system, an authentication server receives, from a backend server, a session creation request for provisioning a contactless card and transmits, to the backend server, a session creation response and a session token. The authentication server receives, from the backend server, an authentication process function request that includes encrypted data associated with the contactless card, decrypts the encrypted data to yield a decrypted authentication code, and compares the decrypted authentication code to an expected authentication code. After an unsuccessful comparison, the authentication server transmits, to the backend server, a notification indicating an unsuccessful authentication to the backend server. After a successful comparison, the authentication server transmits, to the backend server a session identifier associated with the session creation request and a funding primary account number.

First claim

Opening claim text (preview).

What is claimed is: 1 . A transaction provisioning system, comprising: an authentication server in data communication, comprising: a processor, and a memory storing an expected authentication code for a contactless card, wherein the authentication server: receives, from a backend server, a session creation request for provisioning the contactless card, transmits, to the backend server, a session creation response and a session token, receives, from the backend server, an authentication process function request comprising encrypted data associated with the contactless card, decrypts the encrypted data to yield a decrypted authentication code, compares the decrypted authentication code to the expected authentication code, transmits, after an unsuccessful comparison, a notification indicating an unsuccessful authentication to the backend server, and transmits, after a successful comparison, a session identifier associated with the session creation request and a funding primary account number. 2 . The transaction provisioning system of claim 1 , wherein the authentication server: receives, from the backend server, a request to establish a virtual card number (VCN) autofill procedure, receives, from a token server, an eligibility request associated with the contactless card, and transmit, to the token server after determining the contactless card is eligible, a notification indicating eligibility. 3 . The transaction provisioning system of claim 1 , wherein the authentication function request further comprises at least one selected from the group of the session identifier, a consent date, and a device identifier. 4 . The transaction provisioning system of claim 3 , wherein the authentication function request further comprises a wallet identifier associated with a digital wallet. 5 . The transaction provisioning system of claim 3 , wherein the authentication function request comprises one or more risk signals. 6 . The transaction provisioning system of claim 5 , wherein the one or more risk signals comprises at least one selected from the group of a device phone number, an email address, an account risk score, a device risk score, an internet protocol (IP) address, a device geolocation, an account to device bonding identifier, and a device to account bonding age. 7 . The transaction provisioning system of claim 6 , wherein the device phone number and the email address are hashed. 8 . The transaction provisioning system of claim 1 , wherein: the authentication process function request further comprises one or more risk signals, and the one or more risk signals are generated by the backend server. 9 . The transaction provisioning system of claim 8 , wherein prior to transmitting the session identifier and the encrypted funding primary account number, the authentication server: assesses the one or more risk signals, and transmits, to the backend server after determining the authentication process function request is fraudulent based on the one or more risk signals, a notification indicating a fraudulent transaction. 10 . The transaction provisioning system of claim 8 , wherein the authentication server: assesses the one or more risk signals, and determines, prior to transmitting the session identifier and the encrypted funding primary account number, that the authentication process function request is not fraudulent based on the one or more risk signals. 11 . A transaction provisioning method performed by an authentication server comprising a processor and a memory, the method comprising: receiving, from a backend server, a session creation request for provisioning a contactless card; transmitting, to the backend server, a session creation response and a session token; receiving, from the backend server, an authentication process function request comprising encrypted data associated with the contactless card; decrypting the encrypted data to yield a decrypted authentication code; comparing the decrypted authentication code to an expected authentication code associated for the contactless card; transmitting, after an unsuccessful comparison, a notification indicating an unsuccessful authentication to the backend server; and transmitting, after a successful comparison, a session identifier associated with the session creation request and a funding primary account number. 12 . The method of claim 11 , wherein the funding primary account number is encrypted prior to transmission. 13 . The method of claim 11 , wherein: the authentication process function request further comprises one or more risk signals, and the one or more risk signals are generated by the backend server. 14 . The method of claim 13 , further comprising, prior to transmitting the session identifier and the encrypted funding primary account number: assessing the one or more risk signals; and transmitting, to the backend server after determining the authentication process function request is fraudulent based on the one or more risk signals, a notification indicating a fraudulent transaction. 15 . The method of claim 13 , further comprising: assessing the one or more risk signals; and determining, prior to transmitting the session identifier and the encrypted funding primary account number, that the authentication process function request is not fraudulent based on the one or more risk signals. 16 . The method of claim 11 , wherein the authentication function request further comprises at least one selected from the group of the session identifier, a consent date, and a device identifier. 17 . The method of claim 11 , wherein the authentication function request further comprises a wallet identifier associated with a digital wallet. 18 . A non-transitory computer readable medium containing instructions, wherein, upon execution by a processor, the instructions cause the processor to perform procedures comprising: receiving, from a backend server, a session creation request for provisioning a contactless card; transmitting, to the backend server, a session creation response and a session token; receiving, from the backend server, an authentication process function request comprising encrypted data associated with the contactless card; decrypting the encrypted data to yield a decrypted authentication code; comparing the decrypted authentication code to an expected authentication code associated for the contactless card; transmitting, after an unsuccessful comparison, a notification indicating an unsuccessful authentication to the backend server; and transmitting, after a successful comparison, a session identifier associated with the session creation request and a funding primary account number. 19 . The non-transitory computer readable medium of claim 18 , the procedures further comprising: receiving, from the backend server, a request to establish a virtual card number (VCN) autofill procedure; receiving, from a token server, an eligibility request associated with the contactless card; and transmitting, to the token server after determining the contactless card is eligible, a notification indicating eligibility. 20 . The non-transitory computer readable medium of claim 18 , wherein the authentication function request further comprises at least one selected from the group of the session identifier, a consent date, and a device identifier.

Assignees

Inventors

Classifications

  • Risk-dependent, e.g. selecting a security level depending on risk profiles · CPC title

  • of the user plane, e.g. user's traffic · CPC title

  • using certificates or pre-shared keys · CPC title

  • using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title

  • Bill distribution or payments · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2025005555A1 cover?
Systems and methods to provide contactless cards for transactions are disclosed. In an exemplary transaction provisioning system, an authentication server receives, from a backend server, a session creation request for provisioning a contactless card and transmits, to the backend server, a session creation response and a session token. The authentication server receives, from the backend server…
Who is the assignee on this patent?
Capital One Services Llc
What technology area does this patent fall under?
Primary CPC classification G06Q20/352. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Jan 02 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).