Systems and methods for cryptographic authentication of contactless cards
Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. These systems and methods may provide for the secure transmission of sensitive information, such personally-identifiable information. In some examples, the sensitive information may be requested and securely shared when cryptographically signed by the user, and the user may control the access of viewers to the personally identifiable information or end users.
1 . A method of authorization, the method comprising the steps of:
transmitting, by a processor, a request;
generating, by the processor, an authentication diversified key;
generating, by the processor, a session key based on the authentication diversified key;
validating, by the processor, the session key;
authenticating, by the processor responsive to entry of a contactless card into a communication field, one or more login credentials; and
authorizing, by the processor, sharing of information associated with the request.
2 . The method of claim 1 , wherein entry of the contactless card into a communication field comprises at least one selected from the group of a tap, a wave, and a gesture of the contactless card.
3 . The method of claim 1 , wherein the processor is contained within a client device configured to generate the communication field.
4 . The method of claim 1 , wherein the processor is contained within a server in data communication with a client device configured to generate the communication field.
5 . The method of claim 1 , wherein:
the information is stored in a cloud-based storage, and
the cloud-based storage is in data communication with the processor.
6 . The method of claim 1 , wherein the information is stored in a blockchain.
7 . The method of claim 6 , the method further comprising approving, by the contactless card, a blockchain transaction associated with sharing of information.
8 . The method of claim 7 , wherein:
the contactless card contains a private key, and
the contactless card approves the blockchain transaction using the private key.
9 . The method of claim 1 , wherein authorizing, by the processor, sharing of information associated with the request comprises authorizing, by the processor, sharing of one or more portions of the information associated with the request.
10 . The method of claim 9 , wherein the one or more portions of the information comprises proof of age.
11 . The method of claim 9 , wherein the one or more portions of the information comprises one or more credentials associated with a prescription.
12 . A system for authentication, comprising:
a server comprising a processor and a memory,
wherein the server:
transmits a request;
generates an authentication diversified key;
generates a session key based on the authentication diversified key;
validates the session key;
authenticates, responsive to entry of a contactless card into a communication field, one or more login credentials; and
authorizes sharing of information associated with the request.
13 . The system of claim 12 , further comprising:
the contactless card,
wherein the contactless card contains a private key, and
wherein the contactless card signs a transaction associated with sharing of information using the private key.
14 . The system of claim 12 , wherein the request is associated with a predetermined time out period.
15 . The system of claim 12 , wherein the information comprises personally identifiable information.
16 . The system of claim 12 , wherein:
the information is stored in a cloud-based storage, and
the cloud-based storage is in data communication with the server.
17 . The system of claim 12 , wherein the communication field is generated by a client device in data communication with the server.
18 . The system of claim 12 , wherein the server authenticates the one or more login credentials via one or more challenges.
19 . A computer readable non-transitory medium comprising computer executable instructions that, when executed by a processor, perform procedures comprising the steps of:
transmitting a request;
generating an authentication diversified key;
generating, by the processor, a session key based on the authentication diversified key;
validating, by the processor, the session key;
authenticating, by the processor responsive to entry of a contactless card into a communication field, one or more login credentials; and
authorizing, by the processor, sharing of information associated with the request.
20 . The computer readable non-transitory medium of claim 19 , the procedures further comprising receiving, from at least one selected from the group of a third party data requestor, an end user, and a merchant, the request.