IP Library Granted Patent US 10,778,437
Granted Patent B2
US 10,778,437 · App. 16/657,813 · Granted Sep 15, 2020

Systems and methods for cryptographic authentication of contactless cards

Inventors: Kevin Osborn (Newton Highlands, MA); Jeffrey Rule (Chevy Chase, MD); Paul Moreton (Glen Allen, VA); William Duane (Westford, MA); Colin Hart (Arlington, VA); Kaitlin Newman (Washington, DC); Lara Mossler (Farmville, VA); Daniel Herrington (New York, NY); Srinivasa Chigurupati (Long Grove, IL); Ian Prince (Toronto, CA); Wayne Lutz (Fort Washington, MD)
Assignee: CAPITAL ONE SERVICES, LLC
H04L9/3234G06Q20/204G06Q20/3226G06Q20/3278G06Q20/352G06Q20/40H04L9/0866H04L9/14H04L9/3228H04L9/3242H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,778,437
App. No.
16/657,813
Granted
Sep 15, 2020
Kind
B2
Abstract

Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.

Claims (55)

1. An authentication server comprising:

a processor and memory, the memory including a master key, wherein the processor is configured to:

receive a transmission comprising a cryptographic result and encrypted transmission data, wherein:

the cryptographic result includes a counter value,

the cryptographic result is generated using one or more cryptographic algorithms and a diversified key,

the diversified key is generated using a diversified master key, one or more cryptographic algorithms, and the counter value, and

the encrypted transmission data is encrypted using the one or more cryptographic algorithms and the diversified key;

generate an authentication diversified key based on the master key and a unique identifier;

generate a session key based on the authentication diversified key and the cryptographic result;

decrypt the encrypted transmission data and validate the cryptographic result using the one or more cryptographic algorithms and the session key; and

update the counter value for each transmission received.

2. The authentication server of claim 1 , wherein the counter value comprises a one-time passcode.

3. The authentication server of claim 1 , wherein the one or more cryptographic algorithms include a cryptographic MAC function.

4. The authentication server of claim 1 , wherein a unique diversified session key is generated for each transmission.

5. The authentication server of claim 4 , wherein the unique diversified session key is generated using a portion of the counter value.

6. The authentication server of claim 4 , wherein the unique diversified session key is generated utilizing a different counter value.

7. The authentication server of claim 1 , wherein the master key is limited to a predetermined number of uses.

8. The authentication server of claim 1 , wherein the master key is limited to use during a predetermined time period.

9. The authentication server of claim 1 , wherein the authentication server is configured to receive the transmission from a transmitting device via one or more intermediary devices.

10. The authentication server of claim 9 , wherein the transmitting device comprises a contactless card and one of the one or more intermediary devices comprises a smartphone.

11. The authentication server of claim 1 , wherein the encrypted transmission data comprises activation data for a payment card.

12. A method for transmitting data by a transmitting device having a processor and a memory, the memory containing a master key, an identification number, and a counter, the method comprising:

generating a device key using the master key and the identification number;

generating a first session key using the device key and a first portion of the counter and a second session key using the device key and a second portion of the counter, wherein the first portion of the counter is different than the second portion of the counter;

generating a cryptographic result including the counter using one or more cryptographic algorithms and the device key;

generating a cryptogram using the first session key, the cryptogram including the cryptographic result and the identification number;

encrypting the cryptogram using the second session key; and

transmitting the encrypted cryptogram and the cryptographic result.

13. The method of claim 12 , wherein the counter value comprises a one-time passcode.

14. The method of claim 12 , wherein a unique diversified session key is generated for each transmission by the transmitting device.

15. The method of claim 14 , wherein the unique diversified session key is generated using a portion of the counter value.

16. The method of claim 15 , wherein the unique diversified session key is generated utilizing a different counter value.

17. The method of claim 12 , wherein the master key is limited to a predetermined number of uses.

18. The method of claim 12 , wherein the master key is limited to use during a predetermined time period.

19. The method of claim 12 , wherein the transmitting device comprises a contactless card and the cryptogram comprises activation data for the contactless card.

20. A computer readable non-transitory medium comprising instructions for execution on a processor and comprising the steps of:

receiving a transmission comprising a cryptographic result and encrypted transmission data, wherein:

the cryptographic result includes a counter value,

the cryptographic result is generated using one or more cryptographic algorithms and a diversified key,

the diversified key is generated using a diversified master key, one or more cryptographic algorithms, and the counter value, and

the encrypted transmission data is encrypted using the one or more cryptographic algorithms and the diversified key;

generating an authentication diversified key based on a master key and a unique identifier;

generating a session key based on the authentication diversified key and the cryptographic result;

decrypting the encrypted transmission data and validate the cryptographic result using the one or more cryptographic algorithms and the session key; and

updating the counter value for each transmission received.

21. The computer readable non-transitory medium of claim 20 , wherein the counter value comprises a one-time passcode.

22. The computer readable non-transitory medium of claim 20 , wherein the one or more cryptographic algorithms include a cryptographic MAC function.

23. The computer readable non-transitory medium of claim 20 , wherein a unique diversified session key is generated for each transmission.

24. The computer readable non-transitory medium of claim 23 , wherein the unique diversified session key is generated using a portion of the counter value.

25. The computer readable non-transitory medium of claim 23 , wherein the unique diversified session key is generated using a different counter value.

26. The computer readable non-transitory medium of claim 20 , wherein the master key is limited to a predetermined number of uses.

27. The computer readable non-transitory medium of claim 20 , wherein the master key is limited to use during a predetermined time period.

28. The computer readable non-transitory medium of claim 20 , wherein the transmission is received from a transmitting device via one or more intermediary devices.

29. The computer readable non-transitory medium of claim 28 , wherein the transmitting device comprises a contactless card and one of the one or more intermediary devices comprises a smartphone.

30. The computer readable non-transitory medium of claim 29 , wherein the cryptographic result comprises activation data for the contactless card.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2019
From: OSBORN, KEVIN; RULE, JEFFREY; MORETON, PAUL; DUANE, WILLIAM; HART, COLIN; NEWMAN, KAITLIN; MOSSLER, LARA; HERRINGTON, DANIEL; CHIGURUPATI, SRINIVASA; PRINCE, IAN; LUTZ, WAYNE
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 050764/0897 →
Continuity (3)
Continuation 16205119 · Nov 29, 2018
Provisional Application 62740352 · Oct 2, 2018
Related Publication 20200106619A1 · Apr 2, 2020
Cited By (2)
US 12,261,960 US 12,647,271