IP Library › Granted Patent US 10,579,998
Granted Patent B1
US 10,579,998 · App. 16/351,441 · Granted Mar 3, 2020

Systems and methods for cryptographic authentication of contactless cards

Inventors: Kaitlin Newman (Washington, DC); Colin Hart (Arlington, VA); Jeffrey Rule (Chevy Chase, MD); Lara Mossler (Farmville, VA); Sophie Bermudez (Washington, DC); Michael Mossoba (Arlington, VA); Wayne Lutz (Fort Washington, MD); Charles Nathan Crank (Henrico, VA); Melissa Heng (Glen Allen, VA); Kevin Osborn (Newton Highlands, MA); Kimberly Haynes (Reston, VA); Andrew Cogswell (Midlothian, VA); Latika Gulati (Vienna, VA); Sarah Jane Cunningham (Arlington, VA); James Ashfield (Midlothian, VA)
Assignee: CAPITAL ONE SERVICES, LLC
G06Q20/3829G06Q20/352G06Q20/38215H04L9/0838H04L9/0866H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,579,998
App. No.
16/351,441
Granted
Mar 3, 2020
Kind
B1
Abstract

Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.

Claims (53)

1. A system for secure communication comprising:

a transmitting device having a processor and memory, the memory of the transmitting device containing a diversified master key, transmission data and a counter value;

an application comprising instructions for execution on a receiving device having a processor and memory, the memory of the receiving device containing a master key;

wherein the transmitting device is configured to:

generate a diversified key using the diversified master key, one or more cryptographic algorithms, and the counter value,

generate a cryptographic result including the counter value using the one or more cryptographic algorithms and the diversified key,

encrypt the transmission data using the one or more cryptographic algorithms and the diversified key to yield encrypted transmission data, and

transmit the cryptographic result and encrypted transmission data to the application;

wherein the application is configured to:

generate an authentication diversified key based on the master key and a unique identifier;

generate a session key based on the authentication diversified key and the cryptographic result; and

decrypt the encrypted transmission data and validate the received cryptographic result using the one or more cryptographic algorithms and the session key;

wherein, upon the initiation of an operation, the application is further configured to:

request a user identification;

pause the operation until the user identification has been authenticated;

upon authentication of the user identification, complete the operation,

wherein the user identification is provided after entry of the transmitting device into a communication field of the receiving device.

2. The system for secure communication of claim 1 , wherein the receiving device is configured to communicate with one or more servers to authenticate the user identification.

3. The system for secure communication of claim 1 , wherein the user identification is provided by the transmitting device.

4. The system for secure communication of claim 1 , wherein:

the receiving device is a server; and

the cryptographic result and encrypted transmission data are transmitted by the transmitting device to the application via one or more intermediary devices.

5. A method of securing an operation, the method comprising the steps of:

providing a transmitting device comprising a processor and memory and the memory of the transmitting device containing a diversified master key, identification data and a counter value;

providing an application comprising instructions for execution on the receiving device comprising a processor and a memory containing a master key;

wherein the transmitting device is configured to:

generate a diversified key using the diversified master key, one or more cryptographic algorithms, and the counter,

generate a cryptographic result including the counter value using the one or more cryptographic algorithms and the diversified key,

encrypt the identification data using one or more cryptographic algorithms and the diversified key to yield encrypted identification data, and

transmit the cryptographic result and encrypted identification data to the application;

wherein the application is configured to:

generate an authentication diversified key based on the master key and a unique identifier;

generate a session key based on the authentication diversified key and the cryptographic result; and

decrypt the encrypted identification data and validate the received cryptographic result using the one or more cryptographic algorithms and the session key;

initiating an operation;

pausing the operation until a user identification has been authenticated;

authenticating the user identification after entry of the transmitting device into a communication field of the receiving device thereby transmitting encrypted identification data from the transmitting device to the application, wherein the user identification is provided after entry of the transmitting device into the communication field; and

completing the operation.

6. The method of claim 5 , wherein the operation comprises a financial transaction.

7. The method of claim 6 , wherein the step of pausing the operation occurs prior to transmitting financial data associated with the financial transaction.

8. The method of claim 6 , wherein the financial transaction comprises withdrawing funds from an account.

9. The method of claim 5 , wherein the operation comprises accessing a physical space.

10. The method of claim 5 , wherein the operation comprises checking into a hotel.

11. The method of claim 5 , wherein the operation comprises auto-populating an online form.

12. The method of claim 5 , wherein the operation comprises unlocking a vehicle.

13. The method of claim 5 , wherein the operation comprises operating a vehicle.

14. The method of claim 5 , wherein the operation comprises accessing medical records.

15. The method of claim 5 , wherein the operation comprises accessing personal information.

16. The method of claim 5 , wherein the operation comprises calling a customer service agent.

17. The method of claim 5 , wherein the operation comprises changing a hotel reservation.

18. The method of claim 5 , wherein the operation comprises editing a password.

19. The method of claim 5 , wherein the operation comprises editing a mailing address.

20. The method of claim 5 , further comprising the steps of transmitting a passcode to a mobile device and requesting the passcode prior to completing the operation.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2019
From: NEWMAN, KAITLIN; HART, COLIN; RULE, JEFFREY; MOSSLER, LARA; BERMUDEZ, SOPHIE; MOSSOBA, MICHAEL; LUTZ, WAYNE; CRANK, CHARLES NATHAN; HENG, MELISSA; OSBORN, KEVIN; HAYNES, KIMBERLY; COGSWELL, ANDREW; GULATI, LATIKA; CUNNINGHAM, SARAH JANE; ASHFIELD, JAMES
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 050810/0193 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2019
From: NEWMAN, KAITLIN; HART, COLIN; RULE, JEFFREY; MOSSLER, LARA; BERMUDEZ, SOPHIE; MOSSOBA, MICHAEL; LUTZ, WAYNE; CRANK, CHARLES NATHAN; HENG, MELISSA; OSBORN, KEVIN; HAYNES, KIMBERLY; COGSWELL, ANDREW; GULATI, LATIKA; CUNNINGHAM, SARAH JAMES; ASHFIELD, JAMES
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 049244/0061 →
Continuity (2)
Continuation In Part 16205119 · Nov 29, 2018
Provisional Application 62740352 · Oct 2, 2018
Cited By (1)
US 12,725,166