IP Library Granted Patent US 12,010,238
Granted Patent B2
US 12,010,238 · App. 17/892,999 · Granted Jun 11, 2024

Systems and methods for cryptographic authentication of contactless cards

Inventors: Kevin Osborn (Newton Highlands, MA); Jeffrey Rule (Chevy Chase, MD); Srinivasa Chigurupati (Long Grove, IL)
Assignee: CAPITAL ONE SERVICES, LLC
H04L9/3234H04L9/0863H04L9/14H04L9/3228H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,010,238
App. No.
17/892,999
Granted
Jun 11, 2024
Kind
B2
Abstract

Example embodiments of systems and methods for data transmission between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device. The receiving device can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.

Claims (49)

1. A contactless card, comprising:

a processor; and

a memory containing a first private key, a first public key, transmission data, and a counter value,

wherein the contactless card is configured to:

process the counter value using a first cryptographic algorithm and the first private key to yield a cryptographic result including the counter value,

encrypt the transmission data and the cryptographic result using a second cryptographic algorithm and the first public key to yield encrypted transmission data,

generate a second public key based on the first public key, and

transmit the encrypted transmission data and the second public key to a receiving device.

2. The contactless card of claim 1 , wherein the contactless card is further configured to:

sign the counter value using the first private key, and

encrypt the signed counter value using the first public key and the second cryptographic algorithm.

3. The contactless card of claim 1 , wherein the second public key is generated based on the first public key and the counter value.

4. The contactless card of claim 1 , wherein the first public key includes a signed certificate to authenticate an issuer of the first public key.

5. The contactless card of claim 1 , wherein the contactless card is further configured to, prior to transmitting the second public key, encrypt the second public key.

6. The contactless card of claim 1 , wherein the first cryptographic algorithm and the second cryptographic algorithm each include at least one of (i) an asymmetric encryption algorithm, (ii) a digital signature algorithm, (iii) an ElGamal encryption algorithm, (iv) an elliptical curve algorithm, or (v) a Paillier cryptosystem algorithm.

7. The contactless card of claim 6 , wherein the contactless card is configured to select the first cryptographic algorithm and the second cryptographic algorithm.

8. The contactless card of claim 1 , wherein the transmission data comprises activation data for the contactless card.

9. The contactless card of claim 1 , wherein the first private key is specific to the contactless card.

10. The contactless card of claim 1 , wherein the first private key is a global private key.

11. A data transmission system, comprising:

a contactless card comprising:

a card processor, and

a card memory containing a first private key, a first public key, transmission data, and a card counter value, wherein the contactless card is configured to:

process the counter value using a first cryptographic algorithm and the first private key to yield a cryptographic result including the counter value,

encrypt the transmission data and the cryptographic result using a second cryptographic algorithm and the first public key to yield encrypted transmission data,

generate a second public key based on the first public key, and

transmit the encrypted transmission data and the second public key to a receiving device.

12. The system of claim 11 , further comprising:

an application comprising instructions for executing on a receiving device having a receiving device processor and a receiving device memory, the receiving device memory containing a second private key and a receiving device counter value, wherein, when executed on the receiving device, the application is configured to:

receive the encrypted transmission data and the second public key, decrypt the encrypted transmission data using the second private key and a third cryptographic algorithm to yield the transmission data and the cryptographic result, and

decrypt and validate the card counter value using the second public key and a fourth cryptographic algorithm.

13. The system of claim 12 , wherein:

the third cryptographic algorithm is the same as the second cryptographic algorithm, and

the fourth cryptographic algorithm is the same as the first cryptographic algorithm.

14. The system of claim 11 , wherein the card counter value comprises a one-time passcode.

15. The system of claim 11 , wherein the contactless card is further configured to:

sign the counter value using the first private key, and

encrypt the signed counter value using the first public key and the second cryptographic algorithm.

16. The system of claim 11 , wherein the second public key is generated based on the first public key and the counter value.

17. The system of claim 11 , wherein the contactless card is further configured to, prior to transmitting the second public key, encrypt the second public key.

18. A method performed by a contactless card comprising a processor and a memory containing a first private key, a first public key, transmission data, and a counter value, the method comprising:

processing the counter value using a first cryptographic algorithm and the first private key to yield a cryptographic result including the counter value;

encrypting the transmission data and the cryptographic result using a second cryptographic algorithm and the first public key to yield encrypted transmission data;

generating a second public key based on the first public key; and

transmitting the encrypted transmission data and the second public key to a receiving device.

19. The method of claim 18 , further comprising:

signing the counter value using the first private key, and

encrypting the signed counter value using the first public key and the second cryptographic algorithm.

20. The method of claim 18 , wherein the second public key is generated based on the first public key and the counter value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2022
From: OSBORN, KEVIN; RULE, JEFFREY; CHIGURUPATI, SRINVASA
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 060862/0062 →
Continuity (5)
Continuation 16867771 · May 6, 2020
Continuation 16591309 · Oct 2, 2019
Continuation In Part 16205119 · Nov 29, 2018
Provisional Application 62740352 · Oct 2, 2018
Related Publication 20220407712A1 · Dec 22, 2022
Cited By (1)
US 12,732,373