IP Library › Granted Patent US 11,989,724
Granted Patent B2
US 11,989,724 · App. 17/459,121 · Granted May 21, 2024

Systems and methods for cryptographic authentication of contactless cards using risk factors

Inventors: Kevin Osborn (Newton Highlands, MA); Jeffrey Rule (Chevy Chase, MD); James Ashfield (Midlothian, VA); Srinivasa Chigurupati (Long Grove, IL)
Assignee: Capital One Services LLC
G06Q20/38215G06Q20/352G06Q20/3829H04L9/0822H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,989,724
App. No.
17/459,121
Granted
May 21, 2024
Kind
B2
Abstract

Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key. Example embodiments of systems and methods can be used to provide further authentication and added levels of security for transactions.

Claims (58)

1. An authentication system, comprising:

a server comprising one or more processors coupled to a memory,

wherein the server is configured to:

identify a transaction between an account and a merchant,

compare the transaction with a historical transaction pattern for the account, wherein the transaction is conducted at a time that is inconsistent with the historical transaction pattern,

identify the transaction as high risk based on the comparison,

transmit an authentication request,

receive, responsive to the authentication request, a cryptogram,

generate an authentication diversified key based on a master key and a unique identifier,

generate a session key based on the authentication diversified key,

verify the cryptogram based on the session key using a cryptographic algorithm, and

authorize the transaction based on the verified cryptogram.

2. The authentication system of claim 1 , wherein the transaction is conducted in a geographical region that is inconsistent with the historical transaction pattern.

3. The authentication system of claim 1 , wherein the identification of the transaction as high risk is further based on an association of the merchant with a fraudulent transaction.

4. The authentication system of claim 1 , wherein:

the identification of the transaction as high risk is further based on the location of the merchant, and

the location of the merchant is in a geographical region associated with fraudulent transactions.

5. The authentication system of claim 1 , wherein the cryptogram is generated by a contactless card and transmitted to the server via an intermediary device.

6. The authentication system of claim 1 , wherein the server is further configured to transmit a second authentication request for at least one selected from the group of biometric information and a password.

7. The authentication system of claim 1 , wherein the server is further configured to delay the transaction pending the authentication request.

8. The authentication system of claim 1 , wherein the server is further configured to:

prior to transmitting the authentication request, compare the value of the transaction to a threshold, and

transmit the authentication request if the value of the transaction exceeds the threshold.

9. A method of authenticating a transaction, comprising:

identifying, by one or more processors coupled to a memory, a transaction between an account and a merchant;

comparing, by the one or more processors, the transaction to a historical transaction pattern for the account, wherein the transaction is conducted at a time that is inconsistent with the historical transaction pattern;

identifying, by the one or more processors, the transaction as high risk based on the comparison;

transmitting, by the one or more processors, an authentication request;

receiving, by the one or more processors responsive to the authentication request, a cryptogram;

generating, by the one or more processors, an authentication diversified key based on a master key and a unique identifier;

generating, by the one or more processors, a session key based on the authentication diversified key;

verifying, by the one or more processors, the cryptogram based on the session key using a cryptographic algorithm; and

authorizing, by the one or more processors, the transaction based on the verified cryptogram.

10. The method of authenticating a transaction of claim 9 , further comprising transmitting, by the one or more processors, a second authentication request for at least one selected from the group of biometric information and a password.

11. The method of authenticating a transaction of claim 9 , further comprising delaying, by the one or more processors, the transaction pending the authentication request.

12. The method of authenticating a transaction of claim 9 , wherein identifying the transaction as high risk further comprises

determining the transaction is conducted in a geographical region that is inconsistent with the historical transaction pattern.

13. An authentication server, comprising:

one or more processors coupled to a memory,

wherein the one or more processors are configured to: identify a

transaction between an account and a merchant,

compare the transaction with a historical transaction pattern for the account, wherein the transaction is conducted at a time that is inconsistent with the historical transaction pattern,

identify the transaction as high risk based on the comparison,

transmit an authentication request,

receive, responsive to the authentication request, a cryptogram,

generate an authentication diversified key based on a master key and a unique identifier,

generate a session key based on the authentication diversified key,

verify the cryptogram based on the session key using a cryptographic algorithm, and

authorize the transaction based on the verified cryptogram.

14. The authentication server of claim 13 , wherein the identification of the transaction as high risk is further based on an association of the merchant with a fraudulent transaction.

15. The authentication server of claim 13 , wherein:

the identification of the transaction as high risk is further based on the location of the merchant, and

the location of the merchant is in a geographical region associated with fraudulent transactions.

16. The authentication server of claim 13 , wherein the one or more processors are further configured to transmit a second authentication request for biometric information.

17. The authentication server of claim 16 , wherein the biometric information comprises at least one selected from the group of fingerprint information and retina information.

18. The authentication server of claim 13 , wherein the identification of the transaction as high risk is further based on a frequency of the transaction.

19. The authentication server of claim 18 , wherein the frequency of the transaction is abnormal in comparison to the historical transaction pattern.

20. The authentication server of claim 13 , wherein the authentication diversified key is generated on a periodic basis.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2021
From: OSBORN, KEVIN; RULE, JEFFREY; ASHFIELD, JAMES; CHIGURUPATI, SRINIVASA
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 057310/0098 →
Continuity (5)
Continuation 16653420 · Oct 15, 2019
Continuation 16351365 · Mar 12, 2019
Continuation In Part 16205119 · Nov 29, 2018
Provisional Application 62740352 · Oct 2, 2018
Related Publication 20210390536A1 · Dec 16, 2021
Cited By (1)
US 12,519,652