Systems and methods for user authorization and access to services using contactless cards
Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.
1 . A method, comprising:
receiving, from a contactless card by an application comprising instructions for execution on a receiving device having a processor and memory, the memory of the receiving device containing an application key, encrypted transmission data;
decrypting, by the application, the encrypted transmission data using a cryptographic algorithm and the application key;
recording, by the application, information comprising at least one selected from the group of time of authentication, location of authentication, type of contactless card, and type of receiving device; and
accessing, by the application, sensitive information.
2 . The method of claim 1 , further comprising modifying, by the application, the sensitive information.
3 . The method of claim 1 , further comprising transmitting, by the application, the sensitive information.
4 . The method of claim 1 , further comprising destroying, by the application, the sensitive information.
5 . The method of claim 1 , further comprising generating, by the application, additional sensitive information.
6 . The method of claim 1 , further comprising at least selected from the group of modifying, by the application, a hotel reservation and cancelling, by the application, the hotel reservation.
7 . The method of claim 6 , wherein:
the sensitive information comprises insurance information, and
the transmission of the sensitive information facilitates preparation of a bill.
8 . The method of claim 7 , wherein the bill is based on at least one selected from the group of a type of insurance coverage associated with the insurance information and an amount of insurance coverage associated with the insurance information.
9 . The method of claim 1 , wherein:
the sensitive information comprises financial information relating to an asset, and
the method further comprises, by the application, at least one selected from the group of buying the asset, selling the asset, and transferring the asset.
10 . The method of claim 1 , further comprising, after authenticating a user identity and prior to accessing sensitive information, transmitting, by the application, a one-time passcode to a smartphone associated with a user.
11 . A system, comprising:
a contactless card having a processor and memory, the memory of the contactless card containing encrypted transmission data; and
an application comprising instructions for execution on a receiving device having a processor and memory, the memory of the receiving device containing an application key,
wherein the application is configured to:
receive, from the contactless card, the encrypted transmission data,
decrypt the encrypted transmission data using a cryptographic algorithm and the application key,
record information comprising at least one selected from the group of time of authentication, location of authentication, type of contactless card, and type of receiving device, and
access sensitive information.
12 . The system of claim 11 , wherein the sensitive information comprises at least one selected from the group of academic information, financial information, and medical information.
13 . The system of claim 11 , wherein the application is further configured to:
analyze the recorded information, and
generate a user behavior profile.
14 . The system of claim 13 , wherein the application is further configured to:
determine a threshold of variation for the user behavior profile, and
detect an indicator of fraud based on the user behavior profile,
wherein the indicator of fraud includes behavior outside of the user behavior profile and beyond the threshold of variation.
15 . The system of claim 11 , wherein:
the sensitive information comprises insurance information, and
the application is further configured to transmit the insurance information to a device associated with a medical provider.
16 . The system of claim 11 , wherein:
the receiving device comprises a server, and
the contactless card is configured to transmit the encrypted transmission data to the application via one or more intermediary devices.
17 . A non-transitory computer-readable medium containing instructions for execution by a processor of a receiving device, wherein, upon execution by the processor, the instructions configure the processor to perform procedures comprising:
receiving, from a contactless card, encrypted transmission data;
decrypting the encrypted transmission data using a cryptographic algorithm and an application key;
recording information comprising at least one selected from the group of time of authentication, location of authentication, type of contactless card, and type of receiving device; and
accessing sensitive information.
18 . The non-transitory computer-readable medium of claim 17 , wherein:
a vehicle is equipped with the receiving device, and
the procedures further comprise receiving permission to access the vehicle.
19 . The non-transitory computer-readable medium of claim 18 , the procedures further comprising receiving permission to operate the vehicle.
20 . The non-transitory computer-readable medium of claim 19 , wherein operation of the vehicle is permitted during a predetermined time window.