Techniques for call authentication
Various embodiments described herein are directed towards authenticating calls by using one or more keys associated with a specific user. In examples, the user is the sender of a call. In various embodiments, when a call is made, an identifying payload is encrypted using a private key associated with the user. The encrypted identifying payload is appended to the call data stream. The identifying payload may be decrypted with a public key. In embodiments, the identifying payload may be verified. In various embodiments, further authentication methods may be performed by using an object such as a contactless card to provide one or more components of the identifying payload and/or keys. In embodiments, a connection may be made between the sender and the intended recipient of a call based on the verification of the identifying payload.
1 . A computing device, comprising:
a memory configured to store instructions; and
processing circuitry coupled with the memory, the processing circuitry configured to execute the instructions, and when executed, the instructions to cause processing circuitry to:
receive encrypted data from a contactless card, wherein the encrypted data is encrypted using a dynamic key generated using a counter of the contactless card;
generate a call data stream comprising the encrypted data and a call number;
send the call data stream to a service provider system or a second computing device to establish a communication connection with the second computing device, wherein the service provider system or the second computing device is configured to decrypt the encrypted data by generating another dynamic key using a counter maintained by the service provider system or the second computing device; and
establish the communication connection with the second computing device based on a successful authentication performed by the service provider system or the second computing device utilizing the call data stream,
wherein the encrypted data is encrypted with a diversified pair of keys generated by the contactless card, wherein the diversified pair of keys includes the dynamic key, and the service provider system or second computing device is configured to decrypt the encrypted data by generating another pair of diversified keys to authenticate information in the encrypted data, wherein the another pair of diversified keys includes the another dynamic key.
2 . The computing device of claim 1 , wherein the call data stream further comprises an identifier comprising one or more of password information, answers to pre-stored queries, biometric information, an image, or a combination thereof.
3 . The computing device of claim 1 , wherein the call data stream further comprises an identifier comprising audio data, and the audio data is unique to an expected user of the computing device.
4 . The computing device of claim 1 , wherein the call number is associated with the second computing device to establish the communication connection with the second computing device.
5 . The computing device of claim 1 , wherein the encrypted data further includes a shared secret stored on the contactless card.
6 . The computing device of claim 1 , wherein the service provider system comprises a Voice over Internet Protocol (VoIP) network, a Public Switched Telephone Network (PSTN), or a combination thereof.
7 . The computing device of claim 1 , wherein the instructions further cause processing circuitry to determine to establish the communication connection with the second computing device.
8 . A method, comprising:
receiving, by a first computing device, encrypted data from a contactless card, wherein the encrypted data is encrypted using a dynamic key generated using a counter of the contactless card;
generating, by the first computing device, a call data stream comprising the encrypted data and a call number; and
establishing, by the first computing device to a second computing device, a communication connection by sending the call data stream to a system or the second computing device, the system or the second computing device successfully authenticating at least a portion of the encrypted data, wherein the system or the second computing device is configured to decrypt the encrypted data by generating another dynamic key using a counter maintained by the system or the second computing device,
wherein the encrypted data is encrypted with a diversified pair of keys generated by the contactless card, wherein the diversified pair of keys includes the dynamic key, and the service provider system or second computing device is configured to decrypt the encrypted data by generating another pair of diversified keys to authenticate information in the encrypted data, wherein the another pair of diversified keys includes the another dynamic key.
9 . The method of claim 8 , wherein the call data stream further comprises an identifier comprising one or more of password information, answers to pre-stored queries, biometric information, an image, or a combination thereof.
10 . The method of claim 8 , wherein the call data stream further comprises an identifier comprising audio data, and the audio data is unique to an expected user of the computing device.
11 . The method of claim 8 , wherein the call number is associated with the second computing device to establish the communication connection with the second computing device.
12 . The method of claim 8 , wherein the encrypted data further includes a shared secret stored on the contactless card.
13 . The method of claim 8 , wherein the service provider system comprises a Voice over Internet Protocol (VoIP) network, a Public Switched Telephone Network (PSTN), or a combination thereof.
14 . The method of claim 8 , further comprising:
determining, by the first computing device, to establish the communication connection with the second computing device.
15 . A non-transitory computer-readable storage medium, the computer-readable storage medium including instructions that when executed by a computer, cause the computer to:
receive encrypted data from a contactless card, wherein the encrypted data is encrypted using a dynamic key generated using a counter of the contactless card;
generate a call data stream comprising the encrypted data and a call number;
send the call data stream to a service provider system or a second computing device to establish a communication connection with the second computing device, wherein the service provider system or the second computing device is configured to decrypt the encrypted data by generating another dynamic key using a counter maintained by the service provider system or the second computing device; and
establish the communication connection with the second computing device based on a successful authentication performed by the service provider system or the second computing device utilizing the call data stream,
wherein the encrypted data is encrypted with a diversified pair of keys generated by the contactless card, wherein the diversified pair of keys includes the dynamic key, and the service provider system or second computing device is configured to decrypt the encrypted data by generating another pair of diversified keys to authenticate information in the encrypted data, wherein the another pair of diversified keys includes the another dynamic key.
16 . The computer-readable storage medium of claim 15 , wherein the call data stream further comprises an identifier comprising one or more of password information, answers to pre-stored queries, biometric information, an image, or a combination thereof.
17 . The computer-readable storage medium of claim 15 , wherein the call data stream further comprises an identifier comprising audio data, and the audio data is unique to an expected user of the computing device.
18 . The computer-readable storage medium of claim 15 , wherein the call number is associated with the second computing device to establish the communication connection with the second computing device.
19 . The computer-readable storage medium of claim 15 , wherein the encrypted data further includes a shared secret stored on the contactless card.
20 . The computer-readable storage medium of claim 15 , wherein the service provider system comprises a Voice over Internet Protocol (VoIP) network, a Public Switched Telephone Network (PSTN), or a combination thereof.