Key recovery based on contactless card authentication
Systems, methods, apparatuses, and computer-readable media for key recovery based on contactless card cryptograms. A server may receive, from an application, a request to recover a private key for a digital wallet, the request includes a first cryptogram generated by a contactless card. The server may decrypt the first cryptogram based on a key for the contactless card. The server may determine, based on the decryption, a unique identifier of the contactless card and a diversification factor associated with the digital wallet. The server may generate the private key based on the unique identifier and the diversification factor. The server may transmit the private key to the application via a network.
1. A method, comprising:
receiving, by a server from an application, a request to recover a private key for a digital wallet, the request comprising a first encrypted data generated by a contactless card based on a key for the contactless card;
decrypting, by the server, the first encrypted data based on a copy of the key for the contactless card;
determining, by the server based on the decryption of the first encrypted data, a unique identifier of the contactless card and a diversification factor associated with the digital wallet;
generating, by the server based on the unique identifier and the diversification factor, the private key; and
transmitting, by the server to the application via a network, the private key.
2. The method of claim 1 , wherein the diversification factor comprises a primary account number (PAN) sequence number of the contactless card.
3. The method of claim 1 , wherein the diversification factor comprises an application transaction counter (ATC) of the contactless card.
4. The method of claim 1 , further comprising prior to receiving the request:
receiving, by the server from the application, a second encrypted data generated by the contactless card;
decrypting, by the server, the second encrypted data;
generating the private key by the server based on the decryption of the second encrypted data;
generating, by the server, a public key based on the private key and a wallet address for the digital wallet based on the public key; and
transmitting, by the server to the application, the private key, the public key, and the wallet address.
5. The method of claim 4 , wherein the unique identifier of the contactless card and the diversification factor are determined based on the wallet address of the digital wallet.
6. The method of claim 5 , further comprising generating the wallet address of the digital wallet based on the decryption of the first encrypted data.
7. The method of claim 1 , wherein the server further determines a salt value associated with the digital wallet, wherein the server further generates the private key based on the salt value, the method further comprising:
accessing, by the application based on the private key, the digital wallet.
8. A non-transitory computer-readable storage medium, the computer-readable storage medium including instructions that when executed by a processor, cause the processor to:
receive, from an application, a request to recover a private key for a digital wallet, the request comprising a first encrypted data generated by a contactless card based on a key for the contactless card;
decrypt the first encrypted data based on a copy of the key for the contactless card;
determine, based on the decryption of the first encrypted data, a unique identifier of the contactless card and a diversification factor associated with the digital wallet;
generate, based on the unique identifier and the diversification factor, the private key; and
transmit the private key to the application via a network.
9. The computer-readable storage medium of claim 8 , wherein the diversification factor comprises a primary account number (PAN) sequence number of the contactless card.
10. The computer-readable storage medium of claim 8 , wherein the diversification factor comprises an application transaction counter (ATC) of the contactless card.
11. The computer-readable storage medium of claim 8 , wherein the instructions further cause the processor to, prior to receiving the request:
receive, from the application, a second encrypted data generated by the contactless card;
decrypt the second encrypted data;
generate the private key based on the decryption of the second encrypted data;
generate a public key based on the private key and a wallet address for the digital wallet based on the public key; and
transmit, to the application, the private key, the public key, and the wallet address.
12. The computer-readable storage medium of claim 11 , wherein the unique identifier of the contactless card and the diversification factor are determined based on the wallet address of the digital wallet.
13. The computer-readable storage medium of claim 12 , wherein the instructions further cause the processor to generate the wallet address of the digital wallet based on the decryption of the first encrypted data.
14. The computer-readable storage medium of claim 8 , wherein the processor further determines a salt value associated with the digital wallet, wherein the processor further generates the private key based on the salt value.
15. A computing apparatus comprising:
a processor; and
a memory storing instructions that, when executed by the processor, cause the processor to:
receive, from an application, a request to recover a private key for a digital wallet, the request comprising a first encrypted data generated by a contactless card based on a key for the contactless card;
decrypt the first encrypted data based on a copy of the key for the contactless card;
determine, based on the decryption of the first encrypted data, a unique identifier of the contactless card and a diversification factor associated with the digital wallet;
generate, based on the unique identifier and the diversification factor, the private key; and
transmit the private key to the application via a network.
16. The computing apparatus of claim 15 , wherein the diversification factor comprises a primary account number (PAN) sequence number of the contactless card.
17. The computing apparatus of claim 15 , wherein the diversification factor comprises an application transaction counter (ATC) of the contactless card.
18. The computing apparatus of claim 15 , wherein the instructions further cause the processor to prior to receiving the request:
receive, from the application, a second encrypted data generated by the contactless card;
decrypt the second encrypted data;
generate the private key based on the decryption of the second encrypted data;
generate a public key based on the private key and a wallet address for the digital wallet based on the public key; and
transmit, to the application, the private key, the public key, and the wallet address.
19. The computing apparatus of claim 18 , wherein the unique identifier of the contactless card and the diversification factor are determined based on the wallet address of the digital wallet, wherein the instructions further configure the processor to generate the wallet address of the digital wallet based on the decryption of the first encrypted data.
20. The computing apparatus of claim 15 , wherein the processor further determines a salt value associated with the digital wallet, wherein the processor further generates the private key based on the salt value.