US2023252452A1PendingUtilityA1

Secure authentication based on identity data stored in a contactless card

Assignee: CAPITAL ONE SERVICES LLCPriority: Dec 24, 2019Filed: Mar 21, 2023Published: Aug 10, 2023
Est. expiryDec 24, 2039(~13.4 yrs left)· nominal 20-yr term from priority
H04L 2209/805G06Q 20/352G06Q 20/3829G06Q 20/4014G06F 21/34H04L 63/0853G06Q 20/3825G06Q 20/38215G06Q 20/401H04L 2463/082H04L 2463/102H04L 63/0861H04L 63/0442
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems, methods, articles of manufacture, and computer-readable media for secure authentication based on identity data stored in a contactless card associated with an account. An application may receive an indication specifying to perform an operation. The application may receive encrypted data from the card. The application may receive an indication that the authentication server decrypted the encrypted data. The application may determine a type of data required to authorize the operation. The application may receive data comprising passport data or driver license data from the card. The application may determine that the data satisfies a rule for authorizing the operation and authorize performance of the operation based on the authentication server verifying the encrypted data and the data satisfying the at least one rule.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 receiving, by a point-of-sale (POS) terminal, a request to perform an age verification via a contactless card for an age-restricted purchase;   presenting, on a display device of the POS terminal, an indication to provide the contactless card to the POS terminal to perform the age verification;   receiving, by the POS terminal from the contactless card, data indicating an age of a customer associated with the contactless card; and   enabling or restricting, by the POS terminal, the age-restricted purchase based on whether the data indicating the age of the customer meets an age requirement for the age-restricted purchase.   
     
     
         2 . The method of  claim 1 , further comprising prior to receiving the data indicating the age of the customer:
 receiving, by the POS terminal from the contactless card, encrypted data;   transmitting, by the POS terminal, the encrypted data to an authentication server; and   determining, by the POS terminal, that the authentication server decrypted the encrypted data.   
     
     
         3 . The method of  claim 2 , wherein the encrypted data is based on a diversified key of the contactless card, wherein the diversified key is based on another key and a counter value of the contactless card. 
     
     
         4 . The method of  claim 3 , wherein the counter value is synchronized between the contactless card and the authentication server. 
     
     
         5 . The method of  claim 1 , further comprising prior to enabling or preventing the age-restricted purchase:
 receiving, by the POS terminal from the contactless card, a digital signature of the data indicating the age of the customer; and   verifying, by the POS terminal, the digital signature based on a public key for the contactless card.   
     
     
         6 . The method of  claim 1 , wherein the data indicating the age of the customer is based on encrypted government-issued identification stored in the contactless card. 
     
     
         7 . The method of  claim 6 , further comprising prior to enabling or preventing the age-restricted purchase:
 decrypting, by the POS terminal, the encrypted government-issued identification, wherein the decrypted government-issued identification comprises the age of the customer;   determining, by the POS terminal, that the age of the customer does not meet the age requirement for the age-restricted purchase; and   restricting, by the POS terminal, the age-restricted purchase based on the determination that the age of the customer does not meet the age requirement for the age-restricted purchase.   
     
     
         8 . A point-of-sale (POS) terminal, comprising:
 a processor; and   a memory storing instructions that, when executed by the processor, cause the processor to:
 receive a request to perform an age verification via a contactless card for an age-restricted purchase; 
 present, on a display device of the POS terminal, an indication to provide the contactless card to the POS terminal to perform the age verification; 
 receive, from the contactless card, data indicating an age of a customer associated with the contactless card; and 
 enable or restrict the age-restricted purchase based on whether the data indicating the age of the customer meets an age requirement for the age-restricted purchase. 
   
     
     
         9 . The POS terminal of  claim 8 , wherein the instructions further cause the processor to, prior to receiving the data indicating the age of the customer:
 receive, by the POS terminal from the contactless card, encrypted data;   transmit, by the POS terminal, the encrypted data to an authentication server; and   determine, by the POS terminal, that the authentication server decrypted the encrypted data.   
     
     
         10 . The POS terminal of  claim 9 , wherein the encrypted data is based on a diversified key of the contactless card, wherein the diversified key is based on another key and a counter value of the contactless card. 
     
     
         11 . The POS terminal of  claim 8 , wherein the instructions further cause the processor to, prior to enabling or restricting the age-restricted purchase:
 receive, from the contactless card, a digital signature of the data indicating the age of the customer; and   verify the digital signature based on a public key for the contactless card.   
     
     
         12 . The POS terminal of  claim 8 , wherein the data indicate the age of the customer is based on encrypted government-issued identification stored in the contactless card. 
     
     
         13 . The POS terminal of  claim 12 , wherein the instructions further cause the processor to, prior to enabling or restricting the age-restricted purchase:
 decrypt the encrypted government-issued identification, wherein the decrypted government-issued identification comprises the age of the customer;   determine that the age of the customer does not meet the age requirement for the age-restricted purchase; and   restrict the age-restricted purchase based on the determination that the age of the customer does not meet the age requirement for the age-restricted purchase.   
     
     
         14 . A non-transitory computer-readable storage medium, the computer-readable storage medium including instructions that when executed by a processor of a point-of-sale (POS) terminal, cause the processor to:
 receive a request to perform an age verification via a contactless card for an age-restricted purchase;   present, on a display device of the POS terminal, an indication to provide the contactless card to the POS terminal to perform the age verification;   receive, from the contactless card, data indicating an age of a customer associated with the contactless card; and   enable or restrict the age-restricted purchase based on whether the data indicating the age of the customer meets an age requirement for the age-restricted purchase.   
     
     
         15 . The computer-readable storage medium of  claim 14 , wherein the instructions further cause the processor to, prior to receiving the data indicate the age of the customer:
 receive, from the contactless card, encrypted data;   transmit the encrypted data to an authentication server; and   determine that the authentication server decrypted the encrypted data.   
     
     
         16 . The computer-readable storage medium of  claim 15 , wherein the encrypted data is based on a diversified key of the contactless card, wherein the diversified key is based on another key and a counter value of the contactless card. 
     
     
         17 . The computer-readable storage medium of  claim 16 , wherein the counter value is synchronized between the contactless card and the authentication server. 
     
     
         18 . The computer-readable storage medium of  claim 14 , wherein the instructions further cause the processor to, prior to enabling or restricting the age-restricted purchase:
 receive, from the contactless card, a digital signature of the data indicating the age of the customer; and   verify the digital signature based on a public key for the contactless card.   
     
     
         19 . The computer-readable storage medium of  claim 14 , wherein the data indicate the age of the customer is based on encrypted government-issued identification stored in the contactless card. 
     
     
         20 . The computer-readable storage medium of  claim 19 , wherein the instructions further configure the computer to prior to enabling or restricting the age-restricted purchase:
 decrypt the encrypted government-issued identification, wherein the decrypted government-issued identification comprises the age of the customer;   determine that the age of the customer does not meet the age requirement for the age-restricted purchase; and   restrict the age-restricted purchase based on the determination that the age of the customer does not meet the age requirement for the age-restricted purchase.

Join the waitlist — get patent alerts

Track US2023252452A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.