Techniques and systems to perform authentication and payment operations with a contactless card to provide items and services
Embodiments discussed herein are generally directed to systems, devices, methods, and techniques to perform authentication and payment operations with a contactless card to provide items and services.
1 . A system configured to perform authentication and payment operations based on data stored in contactless cards, comprising:
one or more servers comprising one or more processors and memory, the memory coupled with the one or more processors and configured to store instructions that when executed by the one or more processors, cause the one or more processors to:
activate a tap-to-rent feature of a contactless card, wherein activation of the rent feature involves acceptance of terms and conditions for a rental system;
receive, from a computing device of a rental system affixed to or integrated with an item, encrypted data and rental data corresponding to a rental of the item, the encrypted data comprising authentication information received by the computing device from the contactless card via a short-range wireless communication interface of the computing device, the authentication information comprising information associated with a payment account for the contactless card, wherein the rental data comprises an item identifier and a location;
extract the authentication information from the encrypted data;
perform an authentication operation on the authentication information to authenticate the contactless card;
send, to the rental system, a result of the authentication operation, wherein the sending the result of the authentication operation indicates that the contactless card is authentic and indicates acceptance of terms and conditions;
receive, from the rental system, a payment request to pay for the rental of the item in response to the contactless card being authentic;
process the payment request based on the rental data and the information associated with the payment account in the encrypted data; and
release a brake, unlock a lock, unlock a locker, or enable a motor of the item to enable the item via the rental system.
2 . The system of claim 1 , wherein the authentication information comprises a unique identifier to identify the contactless card, and the authentication information is encrypted with a second key and one or more cryptographic algorithms by the contactless card to generate the encrypted data.
3 . The system of claim 1 , wherein the authentication information comprises a counter value, and the one or more processors, to perform the authentication operation, verify the counter value based on a stored counter value.
4 . The system of claim 1 , wherein the authentication information comprises a shared secret, and the one or more processors, to perform the authentication operation, verify the shared secret with a stored shared secret.
5 . The system of claim 1 , wherein the encrypted data is encrypted with a second key generated by the contactless card based on a first key, and the one or more processors, to perform the authentication operation, generate a third key using a stored first key,
decrypt the encrypted data with the third key, and
verify the encrypted data is successfully decrypted with the third key.
6 . The system of claim 1 , wherein the one or more processors receive the encrypted data from a rental server of the rental system based on a command of an application programming interface (API) invoked by the rental server of the rental system invoking an authentication method provided by the one or more servers.
7 . The system of claim 1 , wherein the one or more processors receive the payment request from a rental server of the rental system based on a command of an application programming interface (API) invoked by the rental server of the rental system invoking a payment method provided by the one or more servers.
8 . A computer-implemented method for authentication and payment operations based on data stored in contactless cards, comprising:
activating a tap-to-rent feature of a contactless card, wherein activation of the rent feature involves acceptance of terms and conditions for a rental system;
receiving, by one or more servers comprising one or more processors and memory, from a computing device of a rental system affixed to or integrated with an item, encrypted data and rental data corresponding to a rental of the item, the encrypted data comprising authentication information received by the computing device from the contactless card via a short-range wireless communication interface of the computing device, the authentication information comprising information associated with a payment account for the contactless card, wherein the rental data comprises an item identifier and a location;
extracting, by the one or more servers, the authentication information from the encrypted data;
performing, by the one or more servers, an authentication operation on the authentication information to authenticate the contactless card;
sending, by the one or more servers, to the rental system, a result of the authentication operation, wherein the sending the result of the authentication operation indicates that the contactless card is authentic and indicates acceptance of terms and conditions;
receiving, by the one or more servers, from the rental system, a payment request to pay for the rental of the item in response to the contactless card being authentic;
processing, by the one or more servers, the payment request based on the rental data and the information associated with the payment account in the encrypted data; and
releasing a brake, unlock a lock, unlock a locker, or enable a motor of the item to enable the item via the rental system.
9 . The computer-implemented method of claim 8 , wherein the authentication information comprises a unique identifier to identify the contactless card, and the authentication information is encrypted with a second key and one or more cryptographic algorithms by the contactless card to generate the encrypted data.
10 . The computer-implemented method of claim 8 , wherein the authentication information comprises a counter value, and the authentication operation comprises verifying the counter value based on a stored counter value.
11 . The computer-implemented method of claim 8 , wherein the authentication information comprises a shared secret, and the authentication operation comprises verifying the shared secret with a stored shared secret.
12 . The computer-implemented method of claim 8 , wherein the encrypted data is encrypted with a second key generated by the contactless card based on a first key, and the authentication operation comprises:
generating a third key using a stored first key;
decrypting the encrypted data with the third key; and
verifying the encrypted data is successfully decrypted with the third key.
13 . The computer-implemented method of claim 8 , wherein the one or more servers receive the encrypted data and the payment request from a rental server of the rental system based on respective commands of an application programming interface (API) invoked by the rental server of the rental system invoking an authentication method provided by the one or more servers.
14 . A computer readable non-transitory medium comprising computer-executable instructions that are executed on a processor for authentication and payment operations based on data stored in contactless cards, the computer-executable instructions comprising the steps of:
activating a tap-to-rent feature of a contactless card, wherein activation of the rent feature involves acceptance of terms and conditions for a rental system;
receiving, from a computing device of a rental system affixed to or integrated with an item, rental data corresponding to a rental of the item, and encrypted data from the contactless card, the encrypted data comprising authentication information received by the computing device from the contactless card via a short-range wireless communication interface of the computing device, the authentication information comprising information associated with a payment account for the contactless card, wherein the rental data comprises an item identifier and a location;
extracting the authentication information from the encrypted data;
performing an authentication operation on the authentication information to authenticate the contactless card;
sending, to the rental system, a result of the authentication operation, wherein the sending the result of the authentication operation indicates that the contactless card is authentic and indicates acceptance of terms and conditions;
receiving, from the rental system, a payment request to pay for the rental of the item in response to the contactless card being authentic;
processing the payment request based on the rental data and the information associated with the payment account in the encrypted data; and
releasing a brake, unlock a lock, unlock a locker, or enable a motor of the item to enable the item via the rental system.
15 . The computer readable non-transitory medium of claim 14 , wherein the authentication information comprises a unique identifier to identify the contactless card, and the authentication information is encrypted with a second key and one or more cryptographic algorithms by the contactless card to generate the encrypted data.
16 . The computer readable non-transitory medium of claim 14 , wherein the authentication information comprises a counter value, and the authentication operation comprises verifying the counter value based on a stored counter value.
17 . The computer readable non-transitory medium of claim 14 , wherein the authentication information comprises a shared secret, and the authentication operation comprises verifying the shared secret with a stored shared secret.
18 . The computer readable non-transitory medium of claim 14 , wherein the encrypted data is encrypted with a second key generated from a first key by the contactless card, and the authentication operation comprises:
generating a third key using a stored first key;
decrypting the encrypted data with the third key; and
verifying the encrypted data is successfully decrypted with the third key.