Systems and methods for device authentication and authorization
Example embodiments of systems and methods for data transmission system between transmitting and receiving devices for use in a tap and walk store are provided. In an example embodiment, the transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key. Disclosed systems allow a user to purchase items utilizing the disclosed transmitting device.
1 . An authentication system, comprising:
an authentication server comprising a processor and a memory; and
a contactless card comprising a processor and a memory, the memory of the contactless card containing a card key,
wherein the contactless card is configured to:
generate an identification token,
generate a session key using the card key,
encrypt the identification token using the session key, and
transmit, after an entry of the contactless card into a communication field generated by a receiving device, the identification token; and
wherein the authentication server is configured to:
receive, from the receiving device, an identification message comprising the identification token,
authenticate the identification token,
responsive to a successful authentication of the identification token, transmit, to a retail server, an authentication message,
receive, from the retail server, an approval message, and
transmit, to the receiving device, an authorization token.
2 . The authentication system of claim 1 , wherein:
the receiving device is configured as a point of sale device, and
the receiving device is associated with a merchant.
3 . The authentication system of claim 1 , wherein the authentication server transmits the authentication message after authenticating the identification token.
4 . The authentication system of claim 1 ,
wherein the contactless card is configured to:
receive, from the receiving device, a first request for an identification token,
generate the identification token in response to the first request, and
transmit, to the receiving device after entry of the contactless card into a communication field of the receiving device, the identification token.
5 . The authentication system of claim 4 , wherein the contactless card is further configured to:
receive, from the receiving device, the authorization token, and
receive, from the receiving device, a product message, the product message including at least one product identifier.
6 . The authentication system of claim 5 , wherein:
the memory of the contactless card contains a list of a plurality of product identifiers, and
the contactless card is further configured to update the list of the plurality of product identifiers based on the product message.
7 . The authentication system of claim 6 , wherein the contactless card is further configured to:
receive, from the receiving device, a second product message including a second at least one product identifier from the plurality of product identifiers, and
transmit, after a second entry into the communication field, a second message, wherein the second message includes one of the plurality of product identifiers.
8 . The authentication system of claim 7 , wherein the second message causes the receiving device to obtain, from a pricing server, a price of a product associated with the at least one of the plurality of product identifiers included in the second message.
9 . The authentication system of claim 5 , wherein the contactless card is further configured to:
receive, from a second receiving device, a second request for a second identification token, and
transmit, to the second receiving device after entry of the contactless card into a second communication field of the second receiving device, the authorization token.
10 . The authentication system of claim 4 , wherein the identification message is derived from the identification token.
11 . The authentication system of claim 10 , wherein the authentication server stores the data contained in the identification message.
12 . The authentication system of claim 1 , wherein the authentication server is further configured to, responsive to an unsuccessful authentication the identification token, transmit, to the receiving device, an unsuccessful authentication message.
13 . An authentication method, comprising:
generating, by a contactless card comprising a processor and a memory, the memory of the contactless card containing a card key, an identification token;
generating, by the contactless card, a session key using the card key;
encrypting, by the contactless card, the identification token using the session key;
transmitting, by the contactless card after an entry of the contactless card into a communication field generated by a receiving device, the identification token;
receiving, by an authentication server comprising a processor and a memory from the receiving device, an identification message comprising the identification token;
authenticating, by the authentication server, the identification token;
responsive to a successful authentication the identification token, transmitting, by the authentication server to a retail server, an authentication message;
receiving, by the authentication server from the retail server, an approval message; and
transmitting, by the authentication server to the receiving device, an authorization token.
14 . The authentication method of claim 13 , further comprising, prior to transmitting the authentication message, authenticating, by the authentication server, the identification token.
15 . The authentication method of claim 13 , wherein:
the receiving device is configured as an inventory management device, and
the inventory management device is associated with a particular item for sale.
16 . The authentication method of claim 15 , further comprising decrypting, by the inventory management device, the encrypted identification token.
17 . An authentication server, comprising:
a processor; and
a memory,
wherein the authentication server is configured to:
receive, from a receiving device, an identification message comprising an identification token,
authenticate the identification token,
responsive to a successful authentication of the identification token, transmit, to a retail server, an authentication message,
receive, from the retail server, an approval message, and
transmit, to the receiving device, an authorization token.
18 . The authentication server of claim 17 , wherein the identification message is derived from identification token.
19 . The authentication server of claim 18 , wherein the identification token is generated by a contactless card responsive to a request from the receiving device.
20 . The authentication server of claim 17 , wherein the authentication server is further configured to, after an unsuccessful authentication of the identification message, transmit, to the receiving device, a fraud message.