Systems and methods for cryptographic authentication of contactless cards
First Claim
Patent Images
1. A data transmission system comprising:
- a transmitting device having a processor and memory, the memory of the transmitting device containing a diversified master key, transmission data and a counter value;
an application comprising instructions for execution on a receiving device having a processor and memory, the memory of the receiving device containing the master key;
wherein the transmitting device is configured to;
generate a diversified key using the diversified master key, one or more cryptographic algorithms, and the counter value,generate a cryptographic result including the counter value using the one or more cryptographic algorithms and the diversified key,encrypt the transmission data using the one or more cryptographic algorithms and the diversified key to yield encrypted transmission data, andtransmit the cryptographic result and encrypted transmission data to the application; and
wherein the application is configured to;
generate an authentication diversified key based on the master key and a unique identifier;
generate a session key based on the authentication diversified key and the cryptographic result; and
decrypt the encrypted transmission data and validate the received cryptographic result using the one or more cryptographic algorithms and the session key;
wherein the transmitting device comprises a first contactless card and the receiving device comprises a terminal,wherein the first contactless card is configured to transmit a first account number to the application,the data transmission system further comprising a second contactless card that is configured to transmit a second account number to the application,wherein the application is further configured to;
transmit a first communication to a server, the first communication configured to cause the server to process a payment, the first communication including the first account number and the second account number;
receive a payment amount and determine a first instruction based on a first number, the first number indicative of how many contactless cards transmit information to the application,determine a tap password, wherein the tap password indicates a second number, the second number comprising a number of taps by at least one selected from the group of the first contactless card and the second contactless card to the terminal,receive a second communication from the server indicating that the payment was processed.
1 Assignment
0 Petitions
Accused Products
Abstract
Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.
-
Citations
20 Claims
-
1. A data transmission system comprising:
-
a transmitting device having a processor and memory, the memory of the transmitting device containing a diversified master key, transmission data and a counter value; an application comprising instructions for execution on a receiving device having a processor and memory, the memory of the receiving device containing the master key; wherein the transmitting device is configured to; generate a diversified key using the diversified master key, one or more cryptographic algorithms, and the counter value, generate a cryptographic result including the counter value using the one or more cryptographic algorithms and the diversified key, encrypt the transmission data using the one or more cryptographic algorithms and the diversified key to yield encrypted transmission data, and transmit the cryptographic result and encrypted transmission data to the application; and wherein the application is configured to; generate an authentication diversified key based on the master key and a unique identifier; generate a session key based on the authentication diversified key and the cryptographic result; and decrypt the encrypted transmission data and validate the received cryptographic result using the one or more cryptographic algorithms and the session key; wherein the transmitting device comprises a first contactless card and the receiving device comprises a terminal, wherein the first contactless card is configured to transmit a first account number to the application, the data transmission system further comprising a second contactless card that is configured to transmit a second account number to the application, wherein the application is further configured to; transmit a first communication to a server, the first communication configured to cause the server to process a payment, the first communication including the first account number and the second account number; receive a payment amount and determine a first instruction based on a first number, the first number indicative of how many contactless cards transmit information to the application, determine a tap password, wherein the tap password indicates a second number, the second number comprising a number of taps by at least one selected from the group of the first contactless card and the second contactless card to the terminal, receive a second communication from the server indicating that the payment was processed. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13)
-
-
14. A method for transmitting data by a contactless card having a processor and a memory, the memory containing a master key, an identification number, and a counter, the method comprising:
-
generating a card key using the master key and the identification number; generating a first session key using the card key and a first portion of the counter and a second session key using the card key and a second portion of the counter, wherein the first portion of the counter is different than the second portion of the counter; generating a cryptographic result including the counter using one or more cryptographic algorithms and the card key; generating a cryptogram using the first session key, the cryptogram comprising the cryptographic result and the identification number; encrypting the cryptogram using the second session key; transmitting the encrypted cryptogram and the cryptographic result; transmitting a first account number and a second account number to an application comprising instructions for execution on a receiving device, the receiving device comprising a terminal; transmitting a first communication to a server, the first communication configured to cause the server to process a payment; receiving a payment amount and determining a first instruction based on a first number, the first number indicative of how many contactless cards transmit information the application; determining a tap password, wherein the tap password indicates a second number, the second number comprising a number of taps of each of the contactless cards to the terminal; and receiving a second communication from the server indicating that the payment was processed. - View Dependent Claims (15, 16, 17, 18, 19, 20)
-
Specification