IP Library › Granted Patent US 11,823,182
Granted Patent B2
US 11,823,182 · App. 17/202,954 · Granted Nov 21, 2023

NFC mobile currency transfer

Inventors: Rajko Ilincic (Annandale, VA); Jeffrey Rule (Chevy Chase, MD)
Assignee: Capital One Services, LLC
G06Q20/3829G06Q20/352G06Q20/40G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,823,182
App. No.
17/202,954
Granted
Nov 21, 2023
Kind
B2
Abstract

Various embodiments are generally directed to NFC-based mobile currency transfers. A mobile payment may be programmatically initialized when at least two mobile devices come into NFC communications range. A payment card associated with an account used to fund the currency transfer may be tapped to one or more of the devices to allow a server to validate the currency transfer.

Claims (70)

1. A computer-implemented method, comprising:

receiving, by a server, a first cryptogram from an application executing on a first device, the first cryptogram generated by a contactless card associated with a first account;

incrementing, by the server, a counter value associated with the contactless card to generate a first counter value;

generating, by the server, a first diversified key based on encrypting a master key of the contactless card and the first counter value of the contactless card;

verifying, by the server, the first cryptogram based at least in part on decrypting the first cryptogram using the first diversified key;

receiving, by the server from the application, a request to transfer funds from the first account to a second account, the second account associated with a second device;

receiving, by the server, a second cryptogram from an application executing on the second device, the second cryptogram generated by the contactless card;

incrementing, by the server, the first counter value to generate a second counter value associated with the contactless card;

generating, by the server, a second diversified key based on encrypting the master key and the second counter value;

verifying, by the server, the second cryptogram based at least in part on decrypting the second cryptogram using the second diversified key;

determining, by the server, that the second cryptogram is received within a threshold amount of time of receiving the first cryptogram; and

authorizing, by the server, the request to transfer funds from the first account to the second account based on the verification of the first and second cryptograms and the determination that the second cryptogram is received within the threshold amount of time of receiving the first cryptogram.

2. The method of claim 1 , further comprising:

receiving, by the server from the application executing on the first device, an indication that the first account has been authenticated based on received input comprising one or more of a username and a password for the first account, or biometric credentials for the first account; and

receiving, by the server from the application executing on the second device, an indication that the second account has been authenticated based on received input comprising one or more of a username and a password for the second account, or biometric credentials for the second account.

3. The method of claim 1 , the first and second cryptograms comprising message authentication code (MAC) cryptograms, the method further comprising:

processing, by the server, the request to transfer funds from the first account to the second account.

4. The method of claim 1 , further comprising:

starting a timer by the server responsive to receiving the first cryptogram from the first device, wherein the server determines that the second cryptogram is received from the second device within the threshold amount of time of receiving the first cryptogram from the first device based on the timer.

5. The method of claim 1 , wherein verifying the first cryptogram comprises determining that a customer identifier yielded by decrypting the first cryptogram matches a customer identifier associated with the first account, wherein verifying the second cryptogram comprises determining that a customer identifier yielded by decrypting the second cryptogram matches the customer identifier associated with the first account.

6. The method of claim 5 , wherein the first cryptogram is encrypted by the contactless card based on the first diversified key, wherein the second cryptogram is encrypted by the contactless card based on the second diversified key.

7. The method of claim 6 , wherein the first and second counter values are synchronized between the contactless card and the server.

8. A non-transitory computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code executable by a processor of a server to cause the processor to:

receive a first cryptogram from an application executing on a first device, the first cryptogram generated by a contactless card associated with a first account;

increment a counter value associated with the contactless card to generate a first counter value;

generate a first diversified key based on encrypting a master key of the contactless card and the first counter value of the contactless card;

verify the first cryptogram based at least in part on decrypting the first cryptogram using the first diversified key;

receive, from the application, a request to transfer funds from the first account to a second account, the second account associated with a second device;

receive a second cryptogram from an application executing on the second device, the second cryptogram generated by the contactless card;

increment the first counter value to generate a second counter value associated with the contactless card;

generate a second diversified key based on encrypting the master key and the second counter value;

verify the second cryptogram based at least in part on decrypting the second cryptogram using the second diversified key;

determine that the second cryptogram is received within a threshold amount of time of receiving the first cryptogram; and

authorize the request to transfer funds from the first account to the second account based on the verification of the first and second cryptograms and the determination that the second cryptogram is received within the threshold amount of time of receiving the first cryptogram.

9. The medium of claim 8 , the computer-readable program code executable by the processor to cause the processor to:

receive, from the application executing on the first device, an indication that the first account has been authenticated based on received input comprising one or more of a username and a password for the first account, or biometric credentials for the first account; and

receive, from the application executing on the second device, an indication that the second account has been authenticated based on received input comprising one or more of a username and a password for the second account, or biometric credentials for the second account.

10. The medium of claim 8 , the first and second cryptograms comprising message authentication code (MAC) cryptograms, the computer-readable program code executable by the processor to cause the processor to:

process the request to transfer funds from the first account to the second account.

11. The medium of claim 8 , the computer-readable program code executable by the processor to cause the processor to:

start a timer responsive to receiving the first cryptogram from the first device, wherein the determination that the second cryptogram is received from the second device within the threshold amount of time of receiving the first cryptogram from the first device is based on the timer.

12. The medium of claim 8 , the computer-readable program code to verify the first and second cryptograms executable by the processor to cause the processor to:

determine that a customer identifier yielded by decrypting the first cryptogram matches a customer identifier associated with the first account to verify the first cryptogram; and

determine that a customer identifier yielded by decrypting the second cryptogram matches the customer identifier associated with the first account to verify the second cryptogram.

13. The medium of claim 12 , wherein the first cryptogram is encrypted by the contactless card based on the first diversified key, wherein the second cryptogram is encrypted by the contactless card based on the second diversified key.

14. The medium of claim 13 , wherein the first and second counter values are synchronized between the contactless card and the server.

15. A system, comprising:

a processor; and

a memory storing instructions that when executed by the processor cause the processor to:

receive a first cryptogram from an application executing on a first device, the first cryptogram generated by a contactless card associated with a first account;

increment a counter value associated with the contactless card to generate a first counter value;

generate a first diversified key based on encrypting a master key of the contactless card and the first counter value of the contactless card;

verify the first cryptogram based at least in part on decrypting the first cryptogram using the first diversified key;

receive, from the application, a request to transfer funds from the first account to a second account, the second account associated with a second device;

receive a second cryptogram from an application executing on the second device, the second cryptogram generated by the contactless card;

increment the first counter value to generate a second counter value associated with the contactless card;

generate a second diversified key based on encrypting the master key and the second counter value;

verify the second cryptogram based at least in part on decrypting the second cryptogram using the second diversified key;

determine that the second cryptogram is received within a threshold amount of time of receiving the first cryptogram; and

authorize the request to transfer funds from the first account to the second account based on the verification of the first and second cryptograms and the determination that the second cryptogram is received within the threshold amount of time of receiving the first cryptogram.

16. The system of claim 15 , the memory storing instructions that when executed by the processor cause the processor to:

receive, from the application executing on the first device, an indication that the first account has been authenticated based on received input comprising one or more of a username and a password for the first account, or biometric credentials for the first account; and

receive, from the application executing on the second device, an indication that the second account has been authenticated based on received input comprising one or more of a username and a password for the second account, or biometric credentials for the second account.

17. The system of claim 15 , the first and second cryptograms comprising message authentication code (MAC) cryptograms, the memory storing instructions that when executed by the processor cause the processor to:

process the request to transfer funds from the first account to the second account.

18. The system of claim 15 , the instructions to verify the first and second cryptograms to comprise instructions that when executed by the processor cause the processor to:

determine that a customer identifier yielded by decrypting the first cryptogram matches a customer identifier associated with the first account to verify the first cryptogram; and

determine that a customer identifier yielded by decrypting the second cryptogram matches the customer identifier associated with the first account to verify the second cryptogram.

19. The system of claim 18 , wherein the first cryptogram is encrypted by the contactless card based on the first diversified key, wherein the second cryptogram is encrypted by the contactless card based on the second diversified key.

20. The system of claim 19 , wherein the first and second counter values are synchronized between the contactless card and the system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2021
From: ILINCIC, RAJKO; RULE, JEFFREY
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 055608/0823 →
Continuity (2)
Continuation 16359971 · Mar 20, 2019
Related Publication 20210279724A1 · Sep 9, 2021