IP Library Granted Patent US 11,521,213
Granted Patent B2
US 11,521,213 · App. 16/516,243 · Granted Dec 6, 2022

Continuous authentication for digital services based on contactless card positioning

Inventors: Jeffrey Rule (Chevy Chase, MD); Rajko Ilincic (Annandale, VA)
Assignee: Capital One Services, LLC
G06Q20/4018G06K7/082G06Q20/3278G06Q20/352H04L9/0897H04L63/0853H04W12/065
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,521,213
App. No.
16/516,243
Filed
Jul 18, 2019
Granted
Dec 6, 2022
Kind
B2
Art Unit
3685
USPC
705/75
Abstract

Various embodiments are generally directed to continuous authentication of a user to a digital service based on activity of a contactless card positioned proximate to a computing device on which the digital service operates. For example, a series of periodic status messages may be provided between a client device and the contactless card to verify whether the contactless card remains active, wherein authorization to access the digital service continues while the contactless card is active, and terminates when the contactless card is inactive.

Claims (74)

1. A non-transitory computer-readable storage medium having computer-readable program code stored thereon, the computer-readable program code including instructions which when executed by a processor circuit of a client device cause the processor circuit to perform operations comprising:

receiving, by an application executing on the processor circuit, a request to access a digital service;

performing, by the application, a first authentication by verifying that a first set of encrypted data is associated with a user account;

requesting, by the application based on the first authentication, a second authentication from a contactless card, wherein the contactless card is activated by a magnetic field of the client device;

receiving, by a card reader of the client device, a second set of encrypted data from the contactless card in response to the contactless card being activated, wherein the second set of encrypted data is based on a cryptographic algorithm and a diversified key stored in a memory of the contactless card, the diversified key based on a master key and a counter value of the contactless card, wherein the second set of encrypted data is associated with the user account and is received from the contactless card in a near-field communication (NFC) data exchange format (NDEF) message in response to the contactless card coming into a communication range of the client device;

performing, by the application, the second authentication based on the second set of encrypted data;

authorizing, by the application, access to the digital service in response to the first authentication and the second authentication;

transmitting, by the application at each of a plurality of time intervals, a respective status message of a plurality of status messages to the contactless card by energizing an NFC interface and an antenna to verify that the contactless card is active;

receiving, by the application, a first response of a plurality of responses in response a first status message of the plurality of status messages, wherein each of the plurality of responses are received in one or more NDEF messages communicated by the contactless card;

providing, by the application based on the first response, access to the digital service, without requiring re-authentication;

determining, by the application, that a response to a second status message of the plurality of status messages is not received from the contactless card; and

terminating, by the application, access to the digital service based on the determination that the response to the second status message is not received from the contactless card.

2. The non-transitory computer-readable storage medium of claim 1 , further comprising computer-readable program code including instructions which when executed by the processor circuit cause the processor circuit to perform operations further comprising:

determining, by the application, that a signal strength of the contactless card is below a threshold value, wherein the application determines that the second status message is not received based on the determination that the signal strength of the contactless card is below the threshold value.

3. The non-transitory computer-readable storage medium of claim 2 , further comprising computer-readable program code including instructions which when executed by the processor circuit cause the processor circuit to perform operations further comprising displaying, via a graphical user interface of the client device, the signal strength of the contactless card.

4. The non-transitory computer-readable storage medium of claim 1 , further comprising computer-readable program code including instructions which when executed by the processor circuit cause the processor circuit to perform operations comprising providing the second authentication to a second client device to enable access to a digital service operating on the second client device.

5. The non-transitory computer-readable storage medium of claim 1 , further comprising computer-readable program code including instructions which when executed by the processor circuit cause the processor circuit to perform operations comprising:

sending, by the application, the second set of encrypted data to a server; and

receiving, by the application from the server, the second authentication based on the second set of encrypted data, wherein the counter value of the contactless card is synchronized with a counter value maintained the server.

6. The non-transitory computer-readable storage medium of claim 1 , wherein processing circuitry of the communications interface of the contactless card supports at least one of near field communication (NFC), Bluetooth, and Wi-Fi, and wherein the second set of encrypted data includes at least one of: an encrypted expiration date, an encrypted billing address, and an encrypted card verification value (CVV) associated with the user account.

7. A system, comprising:

a client device operable with a contactless card, the client device including a processor circuit; and

a memory storing instructions which when executed by the processor circuit, cause the processor circuit to perform operations comprising:

receiving, by an application executing on the processor circuit, a request to access a digital service;

performing, by the application, a first authentication by verifying that a first set of encrypted data is associated with a user account;

requesting, by the application based on the first authentication, a second authentication from the contactless card, wherein the contactless card is activated by a magnetic field of the client device;

receiving, by a card reader of the client device, a second set of encrypted data from the contactless card in response to the contactless card being activated, wherein the second set of encrypted data is based on a cryptographic algorithm and a diversified key stored in a memory of the contactless card, the diversified key based on a master key and a counter value of the contactless card, wherein the second set of encrypted data is associated with the user account and is received from the contactless card in a near-field communication (NFC) data exchange format (NDEF) message in response to the contactless card coming into a communication range of the client device;

performing, by the application, the second authentication based on the second set of encrypted data;

authorizing, by the application, access to the digital service in response to the first authentication and the second authentication;

transmitting, by the application at each of a plurality of time intervals, a respective status message of a plurality of status messages to the contactless card by energizing an NFC interface and an antenna to verify that the contactless card is active;

receiving, by the application, a first response of a plurality of responses in response a first status message of the plurality of status messages, wherein each of the plurality of responses are received in one or more NDEF messages communicated by the contactless card;

providing, by the application based on the first response, access to the digital service, without requiring re-authentication;

determining, by the application, that a response to a second status message of the plurality of status messages is not received from the contactless card; and

terminating, by the application, access to the digital service based on the determination that the response to the second status message is not received from the contactless card.

8. The system of claim 7 , the memory storing instructions which when executed by the processor circuit, cause the processor circuit to perform operations further comprising:

determining, by the application, that a signal strength of the contactless card is below a predetermined threshold value or that the client device entered a sleep mode, wherein the application determines that the second status message is not received based on the determination that the signal strength of the contactless card is below the threshold value or that the client device has entered the sleep mode.

9. The system of claim 8 , the memory storing instructions which when executed by the processor circuit, cause the processor circuit to perform operations further comprising displaying the signal strength of the contactless card via a graphical user interface of the client device.

10. The system of claim 7 , further comprising a second client device, wherein the memory stores instructions which when executed by the processor circuit, cause the processor circuit to perform operations further comprising providing the second authentication to a second client device to enable access to a digital service operating on the second client device.

11. The system of claim 10 , wherein the client device is a mobile device, and wherein the second client device is a personal computer.

12. The system of claim 11 , the memory storing instructions which when executed by the processor circuit, cause the processor circuit to perform operations further comprising:

sending, by the application the second set of encrypted data to a server; and

receiving, by the application from the server, the second authentication based on the second set of encrypted data, wherein the counter value of the contactless card is synchronized with a counter value maintained the server.

13. The system of claim 7 , further comprising a physical covering over the client device, the physical covering including a slot through an end wall of the physical covering, the slot defining a set of walls operable to house the contactless card, wherein the slot is disposed along a backside of the client device.

14. A method, comprising:

receiving, by an application executing on a processor circuit of a client device, a request to access a digital service;

performing, by the application, a first authentication by verifying that a first set of encrypted data is associated with a user account;

requesting, by the application based on the first authentication, a second authentication from a contactless card, wherein the contactless card is activated by a magnetic field of the client device;

generating, by the contactless card in response to the contactless card being activated, a second set of encrypted data based on a cryptographic algorithm and a diversified key, wherein the diversified key is generated by the contactless card based on a master key and a counter value of the contactless card;

receiving, by a card reader of the client device and from the contactless card, the second set of encrypted data, wherein the second set of encrypted data is associated with the user account and is received from the contactless card in a near-field communication (NFC) data exchange format (NDEF) message in response to the contactless card coming into a communication range of the client device;

performing, by the application, the second authentication based on the second set of encrypted data;

authorizing, by the application, access to the digital service in response to the first authentication and the second authentication;

transmitting, by the application at each of a plurality of time intervals, a respective status message of a plurality of status messages to the contactless card by energizing an NFC interface and an antenna to verify that the contactless card is active;

receiving, by the application, a first response of a plurality of responses in response a first status message of the plurality of status messages, wherein each of the plurality of responses are received in one or more NDEF messages communicated by the contactless card;

providing, by the application based on the first response, access to the digital service, without requiring re-authentication;

determining, by the application, that a response to a second status message of the plurality of status messages is not received from the contactless card; and

terminating, by the application, access to the digital service based on the determination that the response to the second status message is not received from the contactless card.

15. The method of claim 14 , further comprising:

determining, by the application, that a signal strength of the contactless card is below a threshold value, wherein the application determines that the second status message is not received based on the determination that the signal strength of the contactless card is below the threshold value.

16. The method of claim 15 , further comprising displaying the signal strength of the contactless card via a graphical user interface of the client device.

17. The method of claim 14 , further comprising:

sending, by the application, the second set of encrypted data to a server; and

receiving, by the application from the server, the second authentication based on the second set of encrypted data wherein the counter value of the contactless card is synchronized with a counter value maintained the server.

18. The method of claim 14 , further comprising receiving the contactless card within a slot through an end wall of a physical covering, the slot defining a set of walls operable to house the contactless card, and the slot disposed along a backside of the client device when the client device is coupled with the physical covering.

19. The method of claim 14 , further comprising, based on the termination of the access to the digital service:

receiving, by the application, a third authentication based on verification of a third set of encrypted data associated with the user account;

receiving, by the application via the card reader, a fourth set of encrypted data from the contactless card;

performing, by the application, a fourth authentication based on the second set of encrypted data; and

authorizing, by the application, access to the digital service in response to the third authentication and the fourth authentication.

20. The method of claim 19 , further comprising:

transmitting, by the application at each of an additional plurality of time periods, a respective additional status message of a plurality of additional status messages to the contactless card to verify that the contactless card is active;

receiving, by the application, a first additional response of a plurality of additional responses from the contactless card in response to a first additional status message of the plurality of additional status messages;

providing, by the application based on the first additional response, access to the digital service without requiring re-authentication;

determining, by the application, that an additional response to a second additional status message of the plurality of additional status messages is not received from the contactless card; and

terminating, by the application, access to the digital service based on the determination that the response to the second additional status message is not received from the contactless card.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2019
From: RULE, JEFFREY; ILINCIC, RAJKO
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 049796/0942 →
Continuity (1)
Related Publication 20210019756A1 · Jan 21, 2021
Cited By (79)
US 12,288,206 US 12,450,591 US 12,489,625 US 12,489,747 US 12,493,679 US 12,493,868 US 12,493,869 US 12,494,915 US 12,495,042 US 12,499,433 US 12,505,432 US 12,505,448 US 12,505,450 US 12,506,514 US 12,511,365 US 12,511,638 US 12,511,640 US 12,511,654 US 12,513,123 US 12,519,652 US 12,520,136 US 12,524,768 US 12,526,149 US 12,530,674 US 12,530,937 US 12,532,170 US 12,536,392 US 12,536,522 US 12,536,523 US 12,536,525 US 12,541,667 US 12,548,009 US 12,561,669 US 12,561,673 US 12,567,057 US 12,567,060 US 12,567,069 US 12,574,235 US 12,574,243 US 12,579,532 US 12,580,752 US 12,580,767 US 12,591,875 US 12,591,876 US 12,591,877 US 12,591,885 US 12,592,819 US 12,592,828 US 12,596,545 US 12,596,780 US 12,597,012 US 12,603,163 US 12,603,883 US 12,614,053 US 12,615,154 US 12,621,155 US 12,621,642 US 12,626,241 US 12,626,242 US 12,639,710 US 12,646,062 US 12,646,370 US 12,647,271 US 12,657,572 US 12,658,976 US 12,670,494 US 12,675,766 US 12,675,790 US 12,676,938 US 12,682,371 US 12,683,796 US 12,688,493 US 12,688,508 US 12,694,393 US 12,694,394 US 12,701,141 US 12,706,904 US 12,707,270 US 12,718,038