I'm wondering if anyone has experience with MIFARE DESFire NFC devices or similar ones and can provide input on whether our goal and strategy are possible:
Our goal is to have the MIFARE DESFire EV2 device, when scanned by a user's mobile phone, enable the user to claim a one-time prize via their phone's browser from our website. The prize should only be claimed if the user actually scanned the NFC, and should only be claimed once.
Our thinking is to have the EV2 uses its private key to sign a message that consists of a unique identifier (to prevent replay), such as the time, and send it to our backend server for verification (which holds the private keys). After verification, a unique url will open on the phone's browser, allowing the user to log in/sign up to claim the prize once.
We'd appreciate any input. Our company is also interested in hiring/contracting an engineer to achieve this.