Systems and methods for a transaction card having a cryptographic key
A method of accessing an account includes receiving, from a device, randomly generated seed information and an encrypted key or token generated by a card using the randomly generated seed information via a contactless communication between the card and the device; decrypting the encrypted key or token using a decryption process that includes the randomly generated seed information and the encrypted key or token as inputs in response to determining that the randomly generated seed information does not match previously received seed information; and providing, to the device and based on the decrypted key or token, access to the account.
1 . A method of accessing an account, the method comprising:
receiving, from a device, randomly generated seed information and an encrypted key or token generated by a card using the randomly generated seed information via a contactless communication between the card and the device;
decrypting the encrypted key or token using a decryption process that includes the randomly generated seed information and the encrypted key or token as inputs in response to determining that the randomly generated seed information does not match previously received seed information;
identifying, using the randomly generated seed information, a customer associated with the card; and
providing, to the device and based on the identification of the customer and the decrypted key or token, access to the account.
2 . The method of claim 1 , further comprising:
receiving, from the device, an indication that the customer has successfully logged into the device before receiving the randomly generated seed information.
3 . The method of claim 1 , further comprising:
receiving, from the device, an identification of the device; and
determining that the identification of the device is associated with the identified customer associated with the card.
4 . The method of claim 1 , wherein the decryption process includes a count number as an input and an output that is indicative of an identity of the customer associated with the card.
5 . The method of claim 4 , wherein identifying the customer further comprises cross-referencing the output that is indicative of the identity of the customer with multiple customer profiles stored within a customer database.
6 . The method of claim 5 , wherein identifying the customer further comprises automatically disabling the account in response to a determination that a value of at least one of the randomly generated seed information or a value of the count number had previously been received.
7 . The method of claim 1 , further comprising:
authenticating the customer in response to identifying the customer.
8 . The method of claim 7 , wherein authenticating the customer is further based on additional authentication information received from the device.
9 . The method of claim 8 , wherein the additional authentication information comprises a personal identification number (PIN) or biometric data.
10 . A computing system, comprising:
a processing circuit having one or more processors and one or more memory devices, the processing circuit structured to:
receive, from a device, randomly generated seed information and an encrypted key or token generated by a card using the randomly generated seed information via a contactless communication between the card and the device;
decrypt the encrypted key or token using a decryption process that includes the randomly generated seed information and the encrypted key or token as inputs in response to determining that the randomly generated seed information does not match previously received seed information;
identify, using the randomly generated seed information, a customer associated with the card; and
provide, to the device and based on the identification of the customer and the decrypted key or token, access to the account.
11 . The computing system of claim 10 , wherein the processing circuit is further structured to:
receive, from the device, an indication that the customer has successfully logged into the device before receiving the randomly generated seed information.
12 . The computing system of claim 10 , wherein the processing circuit is further structured to:
receive, from the device, an identification of the device; and
determine that the identification of the device is associated with the identified customer associated with the card.
13 . The computing system of claim 10 , wherein the decryption process includes a count number as an input and an output that is indicative of an identity of the customer associated with the card.
14 . The computing system of claim 13 , wherein the processing circuit is further structured to:
identify the customer by cross-referencing the output that is indicative of the identity of the customer with multiple customer profiles stored within a customer database.
15 . The computing system of claim 14 , wherein the processing circuit is further structured to:
identify the customer by automatically disabling the account in response to at least one of a determination that a value of the randomly generated seed information or a value of the count number had previously been received.
16 . The computing system of claim 10 , wherein the processing circuit is further structured to:
authenticate the customer in response to identifying the customer.
17 . The computing system of claim 16 , wherein the processing circuit is further structured to:
authenticate the customer based on additional authentication information received by the processing circuit from the device.
18 . The computing system of claim 17 , wherein the additional authentication information comprises a personal identification number (PIN) or biometric data.
19 . A non-transitory computer readable medium having computer-executable instructions embodied therein that, when executed by at least one processor of a computing system, cause the computing system to perform operations comprising:
receiving, from a device, randomly generated seed information and an encrypted key or token generated by a card using the randomly generated seed information via a contactless communication between the card and the device;
decrypting the encrypted key or token using a decryption process that includes the randomly generated seed information and the encrypted key or token as inputs in response to determining that the randomly generated seed information does not match previously received seed information;
identifying, using the randomly generated seed information, a customer associated with the card; and
providing, to the device and based on the identification of the customer and the decrypted key or token, access to the account.
20 . The non-transitory computer readable medium of claim 19 , wherein the decryption process includes a count number as an input and an output that is indicative of an identity of the customer associated with the card.