Systems and methods for cryptographic authentication of contactless cards
Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.
1 . A method, comprising:
generating, by a contactless card, encoded data using cryptography with a first key stored on the card;
transmitting, by the contactless card after entry into a contactless communication field, card data comprising the encoded data to a client device;
receiving, by a server, the card data from the client device;
verifying, by the server, the encoded data using a second key associated with the first key;
activating, by the server upon a successful verification, the contactless card;
transmitting, by the server, a return message based on the activation of the contactless card; and
discontinuing, by the contactless card after activation by the server, the generation of data.
2 . The method of claim 1 , wherein the encoded data comprises at least one selected from the group of an account number and a card identifier.
3 . The method of claim 1 , wherein the server transmits a prompt if a number of activation attempts is less than a predetermined threshold.
4 . The method of claim 1 , further comprising:
generating, by the contactless card, the card data,
wherein generating the card data comprises generating, by the contactless card, a one-way hash of original data.
5 . The method of claim 4 , further comprising:
encrypting, by the contactless card, the card data,
wherein encrypting the card data comprises encrypting, by the contactless card, the one-way hash of the original data using the first key.
6 . The method of claim 5 , further comprising:
generating, by the contactless card, a plurality of keys comprising the first key and the second key;
transmitting, by the contactless card, the second key and a card identifier to the client device; and
generating, by the server, instructions based on the second key and the card identifier,
wherein encrypting the card data comprises encrypting a one-way hash of original data using the first key in accordance with the instructions.
7 . The method of claim 5 , wherein:
receiving, by the server, the card data from the client device comprises receiving, by the server, the encrypted card data from the client device, and
the method further comprises:
storing, at the server, a server key, and
decrypting, by the server, the encrypted card data using the server key.
8 . The method of claim 7 , wherein the card data yielded by decrypting the encrypted card data comprises a one-way hash of original data.
9 . The method of claim 1 , further comprising, upon an unsuccessful comparison, transmitting, by the server, a prompt for a second entry of the contactless card into the contactless communication field.
10 . A system for card activation, comprising:
a contactless card comprising a card substrate, a card processor, and a card memory,
wherein the contactless card:
generates card data,
encrypts the card data to yield encrypted card data, and
transmits, after entry into a contactless communication field, the encrypted card data to a user device for communication to a server; and
the server, comprising a server processor and a server memory,
wherein the server:
receives the encrypted card data,
decrypts the encrypted card data to yield the card data,
compares the card data to record data,
activates, upon a successful comparison, the contactless card, and
transmits a return message based on the activation of the contactless card, and
wherein the contactless card discontinues the generation of card data after activation by the server.
11 . The system of claim 10 , wherein the card data comprises at least one selected from the group of a card verification value and a phone number.
12 . The system of claim 10 , wherein:
upon an unsuccessful comparison, the server transmits a notification to the user device, and
the notification is indicative of the unsuccessful comparison.
13 . The system of claim 12 , wherein the user device is associated with a user associated with the contactless card.
14 . The system of claim 12 , wherein the notification instructs the user to send at least one selected from the group of a phone call, an email, and a text message to a service for assistance to activate the contactless card.
15 . The system of claim 12 , wherein the notification comprises at least one selected from the group of a phone call and an email.
16 . The system of claim 10 , wherein:
the contactless card generates a first key and a second key, and
the server memory stores at least one of the first key and the second key.
17 . The system of claim 16 , wherein:
the server memory stores a server counter, and
the server updates the server counter upon each receipt of the encrypted card data.
18 . The system of claim 17 , wherein:
the server generates a first server session key using the first key and the server counter, and
the server generates a second server session key using the second key and the server counter.
19 . The system of claim 10 , wherein:
the card memory stores a first card key and a second card key,
the contactless card generates a first card session key using the first card key, and
the contactless card generates a second card session key using the second card key.
20 . The system of claim 19 , wherein:
the card memory stores a card counter, and
the contactless card updates the card counter upon each transmission of the encrypted card data to the server.
21 . The system of claim 20 , wherein:
the contactless card generates the first card session key using the first card key and the card counter, and
the contactless card generates the second card session key using the second card key and the card counter.
22 . A system for card activation, comprising:
a server, comprising a processor and a memory,
wherein the server:
receives encrypted card data,
decrypts the encrypted card data to yield the card data,
compares the card data to record data,
activates, upon a successful comparison, a contactless card, and
transmits a return message based on the activation of the contactless card, wherein the return message prompts the contactless card to discontinue the generation of card data.
23 . The system of claim 22 , wherein:
upon an unsuccessful comparison, the server transmits a notification to a user device, and
the notification is indicative of the unsuccessful comparison.
24 . The system of claim 22 , wherein:
the memory stores at least one of a first key and a second key,
the card data is encrypted using the first key, and
decrypting the encrypted card data comprises decrypting the encrypted card data using the second key.
25 . The system of claim 24 , wherein:
the card data yielded by decrypting the encrypted card data comprises a one-way hash of original data, and
comparing the card data to the record data comprises comparing the one-way hash of original data or a one-way hash of the record data.
26 . A contactless card, comprising:
a processor; and
a memory,
wherein the contactless card:
generates card data,
encrypts the card data to yield encrypted card data,
transmits, after entry into a near field communication range, the encrypted card data to a client device for authentication by a server, and
discontinues the generation of card data after activation by the server.
27 . The contactless card of claim 26 , wherein:
the memory contains a first key,
the contactless card encrypts the card data using the first key, and
generating the card data comprises generating a one-way hash of original data.
28 . The contactless card of claim 27 , wherein:
the contactless card generates a second key paired with the first key, and
the encrypted card data is configured to be decrypted using the second key to reveal the one-way hash algorithm of the original data.
29 . The contactless card of claim 27 , wherein encrypting the card data comprises encrypting the one-way hash of the original data using the first key.
30 . The contactless card of claim 26 , wherein the card data comprises at least one selected from the group of an account number and a card identifier.