IP Library Granted Patent US 11,195,174
Granted Patent B2
US 11,195,174 · App. 17/101,483 · Granted Dec 7, 2021

Systems and methods for cryptographic authentication of contactless cards

Inventors: Kevin Osborn (Newton Highlands, MA); James Ashfield (Midlothian, VA); Srinivasa Chigurupati (Long Grove, IL); Jeffrey Rule (Chevy Chase, MD)
Assignee: CAPITAL ONE SERVICES, LLC
G06Q20/3829G06Q20/341G06Q20/343G06Q20/352G06Q20/40975H04L9/0861H04L9/3234H04L9/3271G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,195,174
App. No.
17/101,483
Granted
Dec 7, 2021
Kind
B2
Abstract

Example embodiments of systems and methods for data transmission between a contactless card and a client device in support of a FIDO authentication are provided. In an embodiment, upon receipt of a challenge issued by a server in connection with a pending transaction, the contactless card may authorize the client device to utilize a FIDO private key to respond to the challenge. If the response to the challenge is successful, the FIDO authentication may proceed and the transaction may be completed.

Claims (48)

1. A non-transitory memory storing a client application, a master key, and a diversified key, wherein:

the client application comprises instructions for execution on a client device comprising a processor, a memory, and a communication interface, and

the client application is configured to:

receive a challenge from a server;

transmit a verification request to a contactless card;

receive a verification from the contactless card, wherein the verification permits the use of a Fast Identity Online (FIDO) private key;

generate, using the master key and the diversified key, a FIDO key pair including the FIDO private key and a FIDO public key;

sign the challenge using the FIDO private key; and

transmit the signed challenge to the server.

2. The non-transitory memory of claim 1 , wherein the client application is configured to transmit the FIDO public key to the server.

3. The non-transitory memory of claim 1 , wherein the client application stores the FIDO private key in the memory of the client device.

4. The non-transitory memory of claim 1 , wherein the client application is configured to:

store account information and transaction information relating to a transaction, and

transmit a transaction request to the server, the transaction request including account information and transaction information relating to the transaction.

5. The non-transitory memory of claim 1 , wherein the verification is received from the contactless card via a near field communication field generated by the communication interface.

6. The non-transitory memory of claim 1 , wherein the challenge is created by the FIDO public key.

7. The non-transitory memory of claim 1 , wherein the client application is configured to receive a verification input prior to signing the challenge using the FIDO private key.

8. The non-transitory memory of claim 1 , wherein:

the non-transitory memory further stores identification information, and

the client application is configured to generate the FIDO key pair using the identification information with the master key and the diversified key.

9. The non-transitory memory of claim 8 , wherein the identification information comprises a site identifier for a website.

10. The non-transitory memory of claim 1 , wherein:

the non-transitory memory stores a counter value, and

the client application is configured to generate the diversified key using the master key and the counter value.

11. The non-transitory memory of claim 1 , wherein the master key is limited to a predetermined number of uses.

12. The non-transitory memory of claim 1 , wherein the client application is configured to randomly generate the FIDO key pair.

13. A method, comprising:

receiving, by a client application comprising instructions for execution on a client device, a challenge from a server, wherein the client device comprises a processor, a memory, and a communication interface;

transmitting, by the client application, a verification request to a contactless card;

receiving, by the client application, a verification from the contactless card, wherein the verification permits the use of a Fast Identity Online (FIDO) private key;

generating, by the client application using a master key and a diversified key, a FIDO key pair including the FIDO private key and a FIDO public key;

signing, by the client application, the challenge using the FIDO private key; and

transmitting, by the client application, the signed challenge to the server.

14. The method of claim 13 , comprising transmitting, by the client application, the FIDO public key to the server.

15. The method of claim 13 , wherein the client application stores the FIDO private key in the memory of the client device.

16. The method of claim 13 , wherein the challenge is created by a FIDO public key.

17. The method of claim 13 , comprising receiving, by the client application, a verification input prior to signing the challenge using the FIDO private key.

18. A system, comprising:

a processor in data communication with a memory,

wherein the processor is configured to:

receive a challenge from a server;

transmit a verification request;

receive a verification permitting the use of a Fast Identity Online (FIDO) private key;

generate, using a master key and a diversified key, a FIDO key pair including the FIDO private key and a FIDO public key;

sign the challenge using the FIDO private key; and

transmit the signed challenge to the server.

19. The system of claim 18 , wherein the processor is configured to generate the FIDO key pair using identification information with the master key and the diversified key.

20. The system of claim 19 , wherein the identification information comprises a site identifier for a website.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2020
From: OSBORN, KEVIN; ASHFIELD, JAMES; CHIGURUPATI, SRINIVASA; RULE, JEFFREY
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 054445/0783 →
Continuity (4)
Continuation 16590429 · Oct 2, 2019
Continuation In Part 16205119 · Nov 29, 2018
Provisional Application 62740352 · Oct 2, 2018
Related Publication 20210097535A1 · Apr 1, 2021