IP Library › Granted Patent US 12,265,962
Granted Patent B2
US 12,265,962 · App. 18/668,612 · Granted Apr 1, 2025

Systems and methods for cryptographic authentication of contactless cards using risk factors

Inventors: Kevin Osborn (Newton Highlands, MA); Jeffrey Rule (Chevy Chase, MD); James Ashfield (Midlothian, VA); Srinivasa Chigurupati (Long Grove, IL)
Assignee: Capital One Services, LLC
G06Q20/38215G06Q20/352G06Q20/3829H04L9/0822H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,962
App. No.
18/668,612
Filed
May 20, 2024
Granted
Apr 1, 2025
Kind
B2
Examiner
KORSAK, OLEG
Art Unit
2492
USPC
705/44
Abstract

Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key. Example embodiments of systems and methods can be used to provide further authentication and added levels of security for transactions.

Claims (61)

1. A method for card activation, comprising:

reading, by one or more authentication servers, data provided by a contactless card to an application comprising instructions for execution on a client device, the application being in communication with the one or more authentication servers;

verifying, by the one or more authentication servers, a user identity based on the data; and

activating, by the one or more authentication servers after verification of the user identity, a first applet stored in a memory of a contactless card and a second applet stored in the memory of the contactless card,

wherein the first applet is a payment applet, and

wherein the second applet is an authentication applet.

2. The method of claim 1 , further comprising, prior to reading data from the contactless card, prompting, by the application, a user to tap the contactless card against the client device.

3. The method of claim 1 , further comprising:

receiving, by the application from the one or more authentication servers, a notification indicating activation of the contactless card; and

displaying, by the application, a message indicating successful activation of the contactless card.

4. The method of claim 1 , further comprising:

performing, by the second applet, an authentication procedure; and

after a successful authentication, performing, by the first applet, a transaction.

5. The method of claim 4 , wherein the authentication procedure comprises at least one selected from the group of tapping the contactless card on the client device, providing an access credential, generating encoded data using cryptography, and providing biometric information.

6. The method of claim 5 , wherein the biometric information comprises at least one selected from the group of fingerprint information, optical information, facial recognition, and retina information.

7. The method of claim 5 , wherein:

the authentication procedure comprises generating the encoded data using cryptography, and

the method further comprises, prior to generating the encoded data using cryptography:

generating one or more keys associated with the contactless card, and

generating the encoded data using cryptography with at least a first key of the one or more keys.

8. The method of claim 7 , wherein the encoded data using cryptography comprises a message authentication code cryptogram.

9. The method of claim 1 , wherein:

the data comprises an access credential, and

the access credential comprises at least one selected from the group of a password, a personal identification number (PIN), and an identifier of the contactless card.

10. The method of claim 1 , wherein activating the first applet and the second applet enables the contactless card to be used for authorization to complete a purchase.

11. The method of claim 1 , wherein activating the first applet and the second applet enables the contactless card to be used for authorization to access to account information.

12. The method of claim 1 , wherein activating the first applet and the second applet enables the contactless card to be used for authorization to access to restricted information.

13. A system for card activation, comprising:

one or more processors; and

a memory in communication with the one or more processors and comprising instructions for:

reading data provided by a contactless card to a client device, the contactless card having a memory storing first and second applets, wherein the first applet is a payment applet and the second applet is an authentication applet,

verifying a user identity based on the data, and

activating, after verification of the user identity, one or more of the first and second applets of the contactless card.

14. The system of claim 13 , wherein the the memory further comprises instructions for:

transmitting the data to a server,

receiving, from the server, a notification indicating activation of the contactless card, and

displaying a message indicating successful activation of the contactless card.

15. The system of claim 14 , wherein the the memory further comprises instructions for transmitting, to the server, an identification of a type of the client device.

16. The system of claim 15 , wherein the type of the client device comprises at least one selected from the group of a personal computer, a smartphone, a tablet, and a point-of-sale device.

17. The system of claim 15 , wherein the the memory further comprises instructions for transmitting, to the server, additional data based on the type of the client device.

18. The system of claim 17 , wherein the additional data comprises at least one selected from the group of merchant information and device type information.

19. The system of claim 18 , wherein the merchant information comprises at least one selected from the group of a merchant type and a merchant identifier.

20. The system of claim 18 , wherein the device type information comprises at least one selected from the group of point-of-sale data and a point-of-sale identifier.

21. A non-transitory computer readable medium containing instructions for execution on a client device, wherein upon execution by the client device, the instructions cause the client device to perform procedures comprising:

reading data from a contactless card;

verifying a user identity based on the data; and

activating, after verification of the user identity, a first applet stored in a memory of a contactless card and a second applet stored in the memory of the contactless card,

wherein the first applet is a payment applet, and

wherein the second applet is an authentication applet.

22. The non-transitory computer readable medium of claim 21 , the procedures further comprising, prior to reading data from the contactless card, prompting a user to tap the contactless card against the client device.

23. The non-transitory computer readable medium of claim 21 , the procedures further comprising:

transmitting the data to a server,

receiving, from the server, a notification indicating activation of the contactless card, and

displaying a message indicating successful activation of the contactless card.

24. The non-transitory computer readable medium of claim 23 , the procedures further comprising transmitting an identification of a type of client device.

25. The non-transitory computer readable medium of claim 24 , wherein the type of the client device comprises at least one selected from the group of a personal computer, a smartphone, a tablet, and a point-of-sale device.

26. The non-transitory computer readable medium of claim 24 , the procedures further comprising transmits, to the server, additional data based on the type of the client device.

27. The non-transitory computer readable medium of claim 26 , wherein the additional data comprises at least one selected from the group of merchant information and device type information.

28. The non-transitory computer readable medium of claim 21 , wherein activating the first applet and the second applet authorizes a purchase.

29. The non-transitory computer readable medium of claim 21 , wherein activating the first applet and the second applet authorizes access to account information.

30. The non-transitory computer readable medium of claim 21 , wherein activating the first applet and the second applet authorizes access to restricted information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2024
From: OSBORN, KEVIN; RULE, JEFFREY; ASHFIELD, JAMES; CHIGURUPATI, SRINIVASA
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 067463/0175 →
Continuity (6)
Continuation 17459121 · Aug 27, 2021
Continuation 16653420 · Oct 15, 2019
Continuation 16351365 · Mar 12, 2019
Continuation In Part 16205119 · Nov 29, 2018
Provisional Application 62740352 · Oct 2, 2018
Related Publication 20240303642A1 · Sep 12, 2024
References Cited (5)
US 10909527B2 · Rule · 2021 [cited by examiner]
US 11461764B2 · Rule · 2022 [cited by examiner]
KR 101349694B1 · 2014 [cited by applicant]
KR 20140097467A · 2014 [cited by applicant]
KR 20160046161A · 2016 [cited by applicant]
Cited By (1)
US 12,619,986