Secure sharing of credential information
The method securely and efficiently provisions credentials on multiple user devices by using a nonce and provisioning certificate to encrypt and decrypt a target provisioning package, addressing the challenges of secure and automated credential sharing.
Patent Information
- Application Number
- FR2021004707
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-09-24
- Filing Date
- 2021-05-04
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-05-04
AI Technical Summary
Existing systems face challenges in securely and efficiently provisioning credentials on multiple user devices, especially when those devices are not under the user's direct control.
A computer-implemented method that involves providing a nonce and a provisioning certificate to a first user device, which then generates and encrypts a target provisioning package. This package is sent to a second user device, where it is decrypted and used to provision the credential, ensuring secure and automated credential sharing.
The solution enhances the security of credential provisioning by ensuring only intended recipients can authenticate and receive the provisioned credential, while also streamlining the process for efficient credential distribution across multiple devices.
Smart Images

Figure 00000042_0000 
Figure 00000043_0000 
Figure 00000043_0001
Abstract
Description
Title of invention: Secure sharing of credential information
[0001] BACKGROUND
[0002] Portable electronic devices such as smartphones and smartwatches may include secure elements for hosting secure applications and storing relevant credential information. A secure element may be used to selectively share portions of the credential information during contactless transactions (e.g., contactless payment at a payment terminal, contactless collection of a transportation ticket, etc.).
[0003] BRIEF SUMMARY
[0004] A system of one or more computers may be configured to implement particular operations or actions by having software, firmware, hardware, or a combination thereof installed on the system that in operation causes the system to implement the actions. One or more computer programs may be configured to implement particular operations or actions by including instructions that, when executed by a data processing apparatus, cause the apparatus to implement the actions.A general aspect includes a computer-implemented method including, in response to a first request from a first user device, providing a nonce and a provisioning certificate to the first user device, the nonce and the provisioning certificate relating to a provisioning request initiated by the first user device for provisioning a credential for use on a second user device. The computer-implemented method may also include receiving an encrypted target provisioning package from the first user device, the encrypted target provisioning package including the nonce and the provisioning information for provisioning the credential for use on the second user device.The computer-implemented method may also include extracting at least a portion of the provisioning information from the encrypted target provisioning package. The computer-implemented method may also include provisioning the credential for use on the second user device based at least in part on the portion of the provisioning information. Other examples of this aspect include computer systems, devices, and computer programs. corresponding, recorded on one or more computer storage devices, each configured to implement the actions of the processes.
[0005] Another general aspect includes a computer-implemented method including receiving an indication that a user account has successfully logged into a web application associated with a provisioning system. The computer-implemented method may also include receiving an encrypted target provisioning package from an external computing system, the encrypted target provisioning package including provisioning information for provisioning a credential for use on a user device associated with the user account. The computer-implemented method may also include determining a list of user devices eligible to receive the credential based at least in part on the provisioning information, wherein individual user devices in the list of user devices are associated with the user account.The computer-implemented method may also include receiving a selection of a particular user device from the list of user devices. The computer-implemented method may also include provisioning the credential for use on the particular user device based at least in part on the provisioning information. Other examples of this aspect include corresponding computer systems, devices, and computer programs stored on one or more computer storage devices, each configured to implement the actions of the methods.
[0006] Another general aspect includes a computer-implemented method, including receiving, via a messaging system and from a first user device, a request to provision a credential for use on a second user device, the request including a target provisioning package that includes provisioning information. The computer-implemented method also includes validating, using the messaging system, a user account associated with the second device based at least in part on the provisioning information in the target provisioning package. The computer-implemented method also includes storing, using a cloud computing and storage system, the target provisioning package in a remote storage location associated with the user account.The computer-implemented method also includes validating, using a provisioning system, credential information associated with the credential based at least in part on the provisioning information in the target provisioning package. The computer-implemented method also includes provisioning the credential for use on the second . user device based at least in part on validation of the credential information. Other examples of this aspect include corresponding computer systems, devices, and computer programs recorded on one or more computer storage devices, each configured to implement the actions of the methods. Brief description of the drawings
[0007] [Fig.l] illustrates a functional diagram and a descriptive diagram showing an exemplary process for provisioning credentials for use on user devices, according to at least one example.
[0008] [Fig.2] illustrates a functional diagram showing an example architecture or system for enabling provisioning of credentials for use on user devices, according to at least one example.
[0009] [Fig.3] illustrates a user interface for provisioning credentials for use on user devices, according to at least one example.
[0010] [Fig.4] illustrates a user interface for provisioning credentials for use on user devices, according to at least one example.
[0011] [Fig.5] illustrates a user interface for provisioning credentials for use on user devices, according to at least one example.
[0012] [Fig.6] illustrates a user interface for provisioning credentials for use on user devices, according to at least one example.
[0013] [Fig.7A]-7D illustrate a sequence diagram showing example processes for provisioning credentials for use on user devices, according to various examples.
[0014] [Fig.8A] to [Fig.8E] illustrate a sequence diagram showing example processes for provisioning credentials for use on user devices, according to various examples.
[0015] [Fig.9] illustrates a descriptive diagram showing an example process for provisioning a credential for use on a second user device in response to a request from a first user device, according to at least one example.
[0016] [Fig. 10] illustrates a descriptive diagram showing an example process for provisioning a credential for use on a second user device in response to a request from a first user device, according to at least one example.
[0017] [Fig. 11] illustrates a descriptive diagram showing an example process for provisioning a credential for use on a second device user in response to a request from a first user device, according to at least one example.
[0018] [Fig. 12] illustrates a simplified block diagram representing an exemplary architecture for implementing the techniques described herein, according to at least one example. DETAILED DESCRIPTION
[0019] In the following description, various examples will be described. For purposes of explanation, specific configurations and details are presented in order to provide a thorough understanding of the examples. However, it will also be apparent to those skilled in the art that the examples may be practiced without the specific details. In addition, known features may be omitted or simplified so as not to obscure the described example.
[0020] Examples of the present disclosure relate to, among other things, methods, systems, devices, and computer-readable storage media for provisioning credentials on second user devices using provisioning processes initiated by a first user device. The credentials may include any suitable information (e.g., payment information for a credit card, unique account identifiers for electronic passes or tickets, etc.) usable to access a resource (e.g., payment funds, entry to a venue associated with the ticket, access to an attraction in an amusement park, etc.). The credentials may be stored in secure elements on the user devices.A credential once stored in a secure element may be used to perform contactless transactions (e.g., wireless communication with near field communication devices), which may include payments for goods and services, event and venue access, user identification, and the like.
[0021] Typically, credentials are specifically requested by and provisioned on the same user device. For example, if a user wanted to add a new payment card to a secure element on her mobile phone, she would use her mobile phone to implement a predefined process of interacting with a provisioning system to obtain and store a credential for the payment card in the secure element. If the user wanted to add the same payment card to a different user device (e.g., her child's mobile phone), the user would have to go through the same predefined process, but using the different user device. This can be difficult, if not impossible, especially when the user wants to provision credentials on multiple devices that are not not under the control of the user (for example, devices belonging to her friends).
[0022] Turning now to a particular example, a provisioning system is described that allows a user on a first mobile phone to request provisioning of a credential of any type (e.g., an e-pass) on a second mobile phone. Depending on how the request is initiated (e.g., using a third-party web page, from a third-party application on the first mobile phone, or using a digital wallet on the first mobile phone) and whether there is an existing relationship of trust between the user's mobile phones, provisioning on the second mobile phone may be implemented automatically (e.g., without a user on the second mobile phone having to authenticate her account).For example, if the second mobile phone is within a group of trusted devices (e.g., devices that are all associated with a primary account, which belongs to the user of the first mobile phone), provisioning may be implemented automatically on the second mobile phone. If the second mobile phone is not part of the group of trusted devices, the user of the second mobile phone may be required to implement additional steps to authenticate an account of the user of the second mobile phone (e.g., providing cloud storage credentials to confirm that the second mobile phone is logged in to the same account associated with the cloud storage credentials).
[0023] In a particular use case, a user may purchase, on behalf of a group of friends, electronic passes for an amusement park that includes near-field ticketing and collection technology. Such technology may allow users to "tap" their mobile devices on reader devices (e.g., perform a contactless transaction) to enter and exit the park, purchase items within the park, gain access to attractions and shows, etc. Such technology may require each user device to include its own unique credential that is associated with the user's respective electronic ticket. In this manner, the tickets may uniquely identify each friend in the group. Using the provisioning system described herein, the user may provision the electronic passes on behalf of her friends.To begin, the user may open, on their user device (e.g., a source user device), a third-party application hosted by the amusement park. Using this application, the user may request “sharing” purchased e-passes with each friend. Once initiated, the source user device generates a target provisioning package and encrypts the package. provisioning package using a provisioning certificate chain provided by the provisioning system. The target provisioning package is encrypted in such a way that only the provisioning system can decrypt the target provisioning package. After encryption using the provisioning certificate chain, the target provisioning package may be further encrypted by a transport service of a messaging system that sends the target provisioning package (e.g., end-to-end encryption). The messaging system may then send, via a messaging application on the source user device, the encrypted target provisioning package to the target user devices of each of the friends. Depending on the sharing manner, either the provisioning system or the messaging system may store the provisioning package.Each friend then opens the message and is led through a series of prompts, which includes authenticating their account with the provisioning system before the credential is activated on their respective device. After activation, the friends can use their respective user devices to interact with the near-field ticketing and collection technology, and because the credentials are specific to the friends' accounts, the first user is not responsible for the friends' purchases.
[0024] The systems, devices, and techniques described herein provide several technical advantages that improve the security of credential provisioning and transaction processing using secure credentials, and protect user privacy. For example, a nonce and a provisioning certificate (e.g., a provisioning certificate chain) are generated by the provisioning system, shared with the source user device, and used to encrypt a target provisioning package by the source user device. When the target user device authenticates to the provisioning system, it delivers the nonce back to the provisioning system.The provisioning system does not see the identity of the target account associated with the target user device until the target user device contacts the provisioning system for authentication and exchange. In this way, only the intended recipient can authenticate and have the provisioned credential. In some examples, when the target provisioning package is sent only over a messaging system, the target provisioning package may be stored by the messaging system, not within the provisioning system.
[0025] As an additional technical advantage, the techniques described herein provide a more efficient process for provisioning credentials on remote devices. In particular, this process requires fewer clicks, page views, data entry on data entry fields, and the like, compared with conventional methods. For example, in at least one example use case, a parent may send a credential to their child's watch and the child may be able to enter an amusement park by presenting their watch to a reader at the park without the child having interacted with a provisioning user interface at their watch. In this way, the credential may be automatically provisioned on the child's watch without any input from the child.
[0026] When the target user device is a trusted user device, additional technical advantages include bandwidth savings and power consumption savings on the target user device. Both advantages are a result of provisioning occurring in a more or less automated manner. Unlike provisioning on an untrusted user device, a trusted target user device is not required to exchange additional information with the provisioning system to authenticate its associated user account. Instead, the provisioning system relies on other stored information. This reduction in the amount of data that must be transferred between the trusted target user device and the provisioning system results in bandwidth savings and less power consumption.
[0027] Turning now to the figures, [Fig.l] illustrates a functional diagram 102 and a descriptive diagram showing a process 100 for provisioning credentials for use on user devices, according to at least one example. Diagram 102 includes a service provider 104. As described in more detail with respect to [Fig.2], the service provider 104 is any suitable combination of computing devices such as one or more server computers, which may include virtual resources, capable of implementing the functions described with respect to the service provider. Overall, the service provider 104 is configured to manage aspects of provisioning credentials on user devices.
[0028] Diagram 102 also includes a source user device 106 operated by a source user 110 and a target user device 108 operated by a target user 112. The source user device 106 and the target user device 108 may be the same type of user device, but different numbers are used herein to indicate that their respective functions differ depending on whether the device is used to request provisioning, e.g., the source user device 106, or is the device for which provisioning is being requested, e.g., the target user device 108. The user devices 106 and 108 are any suitable electronic user device capable of communicate with other electronic devices over a network such as the Internet, a cellular network, or any other suitable network. In some examples, the user devices 106 and 108 may be a smartphone, a mobile phone, a smartwatch, a tablet, or another user device on which specialized applications may run. The source user device 106 may be uniquely associated with the source user 110 (e.g., via an account used to log in to the source user device 106), and the target user device 108 may be uniquely associated with the target user 112 in the same manner. In some examples, the target user device 108 may also be associated with the source user device 106 via a link with the source user's account 110.This binding may make the target user device 108 a trusted user device with respect to the source user device 106.
[0029] [Fig. 1], 7A-7D, 8A-8E, 9, 10, and 11 illustrate exemplary diagrams showing processes 100, 700, 800, 900, 1000, and 1100 in at least some examples. These processes, and any other processes described herein, are illustrated as logical diagrams, each operation of which represents a sequence of operations that may be implemented in hardware, computer instructions, or a combination thereof. In the context of computer instructions, the operations may represent computer-executable instructions stored on one or more non-transitory computer-readable storage media that, when executed by one or more processors, implement the recited operations.Generally, computer-executable instructions include routines, programs, objects, components, data structures, and the like that perform particular functions or implement particular data types. The order in which the operations are described should not be construed as limiting, and any number of the described operations may be combined in any order and / or in parallel to implement the methods.
[0030] Additionally, some, any, or all of the processes described herein may be implemented under the control of one or more computer systems configured with specific executable instructions and may be implemented as code (e.g., executable instructions, one or more computer programs, or one or more applications) collectively executing on one or more processors, by hardware, or combinations thereof. As noted above, the code may be stored on a non-transitory computer-readable storage medium, e.g., as a computer program including a plurality of instructions executable by one or more processors.
[0031] The process 100 begins at 114 with the service provider 104 receiving, from the source user device 106, a request to provision a credential on the target user device 108. The request may be initiated within a third-party application. Under a trusted device scenario, the request may include a target provisioning package (PTP) 116. As described in more detail herein, the PTP 116 may have been generated by the source user device 106, in response to receiving a nonce from the service provider 104. The PTP 116, or at least some portion thereof, may also be sent to the target user device 108. In some examples, the PTP 116 is sent to the target user device 108 via a messaging application hosted by the service provider 104.In this manner, the PTP 116 may be copied and stored by the service provider 104 and also distributed to the target user device 108. In some examples, such as in an untrusted device scenario, the service provider 104 may receive the PTP 116 from the target user device 108 after the target user device 108 receives the PTP 116 from the source user device 106.
[0032] At 118, the service provider 104 may decrypt and extract provisioning information from the PTP 116. This may include extracting credential information to obtain the credential from an external computing system that hosts the third-party application and maintains credentials associated with the third-party application or service. For example, the external computing system may be a banking system and the credential information may be used by the service provider 104 to interact with the banking system to request the appropriate credential to fulfill the request received at 114.
[0033] At 120, the service provider 104 may identify the target user device 108 based at least in part on the provisioning information. In some examples, the PTP 116 may identify the target user device 108, and the block 120 may be used to determine the identity of the target user device 108 based on the provisioning information. The identity of the target user device 108 may be used to communicate with the external computing system as described previously.
[0034] At 122, the service provider 104 may provision the credential 124 for use on the target user device 108 based at least in part on the provisioning information. For example, this may include registering the target user device 108 to receive notifications relating to the credential 124. This may also include the service provider 104 sending a provisioning batch that includes the credential 124. to the target user device 108. In addition to the credential 124, the provisioning bundle may include image(s) and metadata to represent the credential in the third-party application or within a digital wallet on the target user device 108. The target user device 108 may store the credential 124 and, in some examples, the image(s) and metadata in a secure element on the target user device 108.
[0035] [Fig. 2] illustrates a block diagram showing an exemplary architecture or system 200 for enabling provisioning of credentials for use on user devices, according to at least one example. The system 200 includes some elements shown in [Fig. 1]. In particular, the system 200 includes the service provider 104, the source user device 106, and the target user device 108. Arrows between elements of the system 200 generally indicate that these elements are communicatively coupled, either via a wired network connection, a wireless connection, or in any other suitable manner. However, the arrows should not be perceived as limiting because at least some elements can communicate with each other, although there are no arrows between them.
[0036] Beginning with the service provider 104, the service provider 104 may be operated by the same entity that sells the user device 106 and 108. In this manner, the user devices 106 and 108 may generally operate in an ecosystem hosted by the service provider 104. The service provider 104 includes a messaging system 202, a provisioning system 204, and a cloud storage and computing system 206. The messaging system 202 is generally configured to host messaging applications (e.g., one of the applications 212) on the user devices 106 and 108.
[0037] The user devices 106 and 108 each respectively include one or more applications 212 and 214, and a secure element 216 and 218. The secure elements 216 and 218 are used to store credentials, metadata, images, and other such information relating to the credentials. In some examples, the secure elements 216 and 218 provide a platform for performing contactless transactions with payment terminals, entry terminals, and the like. In some examples, the secure elements 216 and 218 may be omitted from one or both of the user devices 106 and 108.
[0038] The applications 212 and 214 may be any suitable computer program or software application developed to run on a mobile device. The applications 212 and 214 may be preloaded on the user devices 106 and 108 (e.g., a messaging application, a wallet application mobile application, an email application, etc.) and / or may be downloaded from an application store. In some examples, at least some of the applications available in the application store may be developed by third parties, e.g., a party other than the developer of the preloaded applications and / or the operating system of the user devices 106 and 108. In some examples, these "third-party applications" may allow access to certain credentials. For example, a third-party banking application on the user device 106 may be used to load a credit card credential into the secure element 216, and share the credential with the user device 108. As described herein, doing so may include interaction of the user device 106 with an issuance system 220.As a further example, a third-party amusement park application on the user device 106 may provide access to electronic pass credentials for use in an amusement park, and to share the electronic pass credential with the user device 108. In some examples, the user device 106 may be used to share credential information obtained from a third-party application (e.g., the banking application) for credentials that are not stored in the secure element 216.
[0039] The messaging system 202 includes an account registry 208 and a transport service 210. The account registry 208 may be used to store registered device identifiers (e.g., phone numbers, email addresses, etc.) to which users may receive messages and from which users may send messages. In some examples, the device identifiers may be associated with the user accounts used to log in to the user devices. The transport service 210 is generally configured to enable the transport of messages by and between user devices that include the messaging applications. For example, the transport service 210 may enable messages to be sent between the user device 106 and the user device 108.In some examples, the transport service 210 may include functionality to enable end-to-end encryption of messages sent between the user devices 106 and 108 and other devices. For example, a messaging application on the user device 106 may be used to send an encrypted message including a PTP to the user device 108. In some examples, the messaging application encrypts and decrypts messages using keys that are not known to the messaging system 202 and / or the service provider 104. In some examples, either or both of the messaging system 202 and the cloud computing and storage system 206 may be operated by entities separate from the operator of the provisioning system 204. For example, . A third party entity may operate the messaging system 202 (e.g., a free cross-platform messaging service, a dedicated messaging application of a social media site, etc.). In this example, the PTP may be encrypted by the user device 106 and sent via the third party's messaging system. When received by the user device 108, the PTP may be provided to the digital wallet on the user device 108 and the user device 108 may authenticate to the provisioning system 204 using the cloud storage and computing system 206 and share the PTP with the provisioning system 204.
[0040] Turning now to the provisioning system 204, the provisioning system 204 includes an account database 222, a provisioning service 224, and a transaction processing service 226. Generally, the account database 222 may be used to store account information for users and their respective devices that interact with the provisioning system 204. The provisioning service 224 may be configured to implement operations described herein with respect to [Fig. 10] and 11 relating to the provisioning of credentials on user devices. Thus, the provisioning service 224 may include functionality to decrypt certain encrypted messages, extract data, and communicate with the user devices 106 and 108, the messaging system 202, the cloud computing and storage system 206, and the delivery system 220.The 226 Transaction Processing Service can be used to process payments and other contactless transactions.
[0041] Generally, the cloud storage and computing system 206 allows users to store data such as documents, photos, videos, etc. on remote servers, provides a means to wirelessly back up data to user devices, and provides data synchronization between user devices. The cloud storage and computing system 206 includes an account registry 228 and an authentication service 230. The account registry 228 is used to store account information including registered device identifiers (e.g., phone numbers, email addresses, etc.) for users who use the cloud storage and computing system 206. In some examples, an account with the cloud storage and computing system 206 may be required to initialize the user devices 106 and 108.In some examples, at least some of the account information in account ledger 228 is identical to at least some of the account information in account ledger 208. For example, a user may use the same email address (e.g., username) for both systems and may . associate the same device identifiers for both systems. In this manner, the same user devices may be used to receive messages, according to the account register 208, and access remote files, according to the account register 228. In some examples, the account register 228 may be used as a point of truth for authentication of a user / user devices requesting credentials. The authentication service 230 may implement the authentication function, as described herein.
[0042] Generally, the issuance system 220 may be operated by an entity other than the entity that operates the service provider 104. In particular, the issuance system 220 may be an example of an external computer system that issues credentials. For example, the issuance system 220 may be associated with a bank that issues a credit card, a theme park that issues an electronic pass, and any other type of entity that may issue a credential for the reasons described herein. The issuance system 220 includes an account database 232 and a credential service 234. Generally, the account database 232 is used to store account information that is specific to the issuance system 220.For example, this may be a user's login information for a bank account that belongs to the entity that operates the issuing system 220. The account information may also identify associations between user devices having third-party applications published by the issuing system 220 and users whose account information is stored in the account database 232. The credential service 234 may be configured to generate credentials for transport to the user devices 106 and 108 in response to requests and in any other suitable manner described herein.
[0043] [Fig. 3]-6 illustrate exemplary user interfaces for provisioning credentials for use on user devices, according to various examples. Beginning with [Fig. 3], in [Fig. 3] are illustrated user interfaces 302 and 304 presented on the source user device 106. The user interface 302 is presented in a third-party application and provides a button 308 allowing a user to add one or more passes 306 (e.g., an e-pass credential) associated with the third-party application to the source user device 106. For example, the third-party application may be hosted by the issuance system 220 and may relate to a service offered by the issuance system 220 (e.g., an amusement park including near-field ticketing and collection technology).
[0044] A selection of the button 308 may cause the source user device 106 to present the user interface 304. The user interface 304 provides a graphical representation of the pass 306 and indicates that three passes are available for addition to the digital wallet (e.g., the secure element) on the source user device 106. Three passes may be available for addition to the wallet because the user previously purchased three tickets at the amusement park, for example, using the third-party application or using a different method. In either case, the third-party application may include information regarding the number of tickets and for whom the tickets are intended. For example, the three passes may uniquely identify three users (e.g., the purchaser and two friends, the purchaser and their two children, etc.).To add the passes to the user's wallet, the user can select button 310. .
[0045] A selection of button 310 may cause the source user device 106 to present user interface 312 in [Fig. 4]. User interface 312 acts as a confirmation that passes 306 have been added to the digital wallet of the source user device 106. From the digital wallet and / or the third-party application, the user may choose to share passes 306, as shown in user interface 314 in [Fig. 4]. In particular, the user may select button 316 to share passes 306 with others, or select button 318 to end at that time instead of sharing.
[0046] A selection of button 316 may cause the source user device 106 to present user interface 320, as shown in [Fig. 5]. User interface 320 provides the user with an option to select which of the three passes 306 to share by selecting recipients using button 322. For example, a selection of button 322 may cause the source user device 106 to scroll through a list of devices that may receive pass 306 and which one is associated with the source user device 106 (e.g., is a registered contact, or is part of a circle of trust, etc.). In some examples, the list may also be sorted to include those accounts associated with devices that are likely to receive and store credentials such as pass 306.Since the passes 306 may uniquely identify users, the list may be pre-populated to match the identities of the users identified by the passes 306. In some examples, the user of the source user device 106 may search for and select users with whom to share the pass 306 using the messaging application on the source user device 106. In some examples, the user interface 320 may be used to initiate sharing of the passes 306 without the user having to access the messaging application. The fact that the message was sent, . However, it can be stored in a conversation with the user with whom the 306 pass was shared. If the user does not wish to share the passes at this time, they can select the 324 button to end the sharing flow.
[0047] A selection of button 322 (and any corresponding selections of recipients, as described herein) may cause the source user device 106 to send a message to the target user device 108, which includes a user interface 326. The user interface 326 is a messaging application on the target user device 108 that indicates that a new message has been received from Jennifer. In this example, Jennifer is the user of the source user device 106 who has chosen to share the passes 306 with the target user device 108. In this example, the target user device 108 has received all three passes 306. In some examples, the target user device 108 may receive a single pass 306. To add the passes 306, the user may select an add button 328 included in the user interface 326.This will add the passes to the user's digital wallet.
[0048] A selection of the view button 328 may cause the target user device 108 to present a user interface 330. The user interface 330 may be presented within the third-party application (e.g., amusement park application) on the target user device 108, within the messaging application on the target user device 108, or within the digital wallet on the target user device 108. The user may quickly swipe left to right and right to left across the passes 306 to view the passes 306. To add the passes to the digital wallet on the target user device 108, the user may select the add to wallet button 332.Selecting the add to wallet button 332 will cause the target user device 108 to perform any additional authentication to download the credentials associated with the passes 306. This may include the target user device 108 communicating with the service provider 104 and / or the issuing system 220. Alternatively, the user may cancel the addition of the passes 306 by selecting a cancel button 334.
[0049] Once the passes 306 are added to the virtual wallet, the passes may be visible in the virtual wallet, as represented by the user interface 336 in [Fig. 6]. In particular, a first pass 306a is represented as belonging to “Amy,” a second pass may belong to “Jennifer” (the owner of the target user device 108), and a third pass may belong to “Charles” (the owner of the source user device 106). From the digital wallet, the user may redeem the passes. pass 306 one at a time or all at once using button 338. Redeeming passes 306 may include activating the passes for use within a certain period of time. If, instead of passes 306, the credentials were credit cards, button 338 may be necessary because credit card credentials do not need to be "redeemed," for example; they can be activated once added to the virtual wallet. Tickets, passes, and the like, however, may be redeemed for use.
[0050] [Figs. 7A] to 7D illustrate a sequence diagram 700 showing example processes for provisioning credentials for use on user devices, according to various examples. In particular, the sequence diagram 700 represents processes for provisioning credentials within a third-party application, such as the process described with respect to [Figs. 3] to 6.
[0051] As elements in the sequence diagram 700, [Figs. 7A] through 7D include the user 702 (e.g., the source user 110), a delivery application 704 (e.g., a third-party application), a source provisioning device 706 (e.g., the source user device 106), a target provisioning device 708 (e.g., the target user device 108), a provisioning system 710 (e.g., the provisioning system 204), and an external computing system 712 (e.g., the delivery system 220). The delivery application 704 may run on the source provisioning device 706.
[0052] Beginning with [Fig.7A], at 714, the user 702 selects items to be provisioned. This may include selecting to share a pass, ticket, credit card, or the like with a different user. At 716, the issuing application 704 sends a message to the external computing system 712 that requests information for provisioning. In response, at 718, the external computing system 712 sends a provisioning credential identifier (e.g., an identifier that identifies the credential to be shared) and a sharing instance identifier (e.g., an identifier that identifies the sharing instance) to the issuing application 704. These identifiers are sent using a secure transport mechanism.
[0053] At 720, the issuing application 704 uses the information received from the external computing system 712 at 718 to cause the source provisioning device 706 to present a "share view" to the user 702, at 722. At 724, within a box 726 representing a loop, the user 702 selects, at the source provisioning device 706, a provisioning target for provisioning the credential identifier. In response, at 728, the source provisioning device 706 requests one or more certificates. provisioning to the provisioning system 710. The provisioning certificate (e.g., a certificate chain) is used to provide an encryption key that the source provisioning device 706 can use for encryption of the target provisioning package. This ensures that the encryption key came from the service provider and is valid. The certificate chain can be validated by the provisioning system 710 by ensuring that the provisioning certificate is anchored to a production root certificate authority and has not been revoked, among other things. In response to this request, at 730, the provisioning system 710 sends a nonce and the provisioning certificate to the source provisioning device 706. At 732, the source provisioning device 706 uses the nonce and other information to generate a target provisioning package (e.g., the PTP 116).
[0054] Looking now at [Fig. 7B], at 734, the source provisioning device 706 encrypts the target provisioning package that was generated at 732. This may also include encryption of the certificate. Block 726 represents another sequence that is implemented when the target provisioning device 708 is outside a "circle of trust." As described herein, user accounts may be associated to allow sharing such as via family members or others who have been invited into the circle of trust. Devices and accounts inside the circle of trust may be treated differently during credential provisioning, as shown in block 726. Block 728 in [Fig. 7C] represents a sequence for provisioning when the target provisioning device 708 is inside the circle of trust.In some examples, a membership of the recipient (e.g., the user of the target provisioning device 708) in the circle of trust of the sender (e.g., the user of the source provisioning device 706) is validated by the provisioning system 710 at the time of the credential exchange.
[0055] Returning to box 726, at 730, the source provisioning device 706 sends the encrypted provisioning target to the target provisioning device 708. In some examples, this may be implemented using a messaging application and the messaging system 202. For example, the encrypted provisioning target may arrive in a conversation in the messaging application on the target provisioning device 708, as depicted in the user interface 326. At 732, the target provisioning device 708 begins the in-application provisioning process by sending the encrypted target provisioning package to the provisioning system, as generally depicted in the user interface 330.
[0056] At 734, the provisioning system 710 may decrypt the encrypted target provisioning package, after which, at 736-740, the provisioning system 710 may extract provisioning information from the target provisioning package, e.g., a credential identifier, a share instance identifier, and a card configuration identifier. The credential identifier and the share instance identifier were previously obtained by the external computing system 712 from the issuing application 704 at 718. The card configuration identifier is used to identify the correct partner to obtain the provisioning credential, at 746. At 744, the provisioning system 710 validates a provisioning policy that is included in the target provisioning package.
[0057] At 746, the provisioning system 710 sends a request to obtain a provisioning credential to the external computing system 712. This request may include at least a portion of the provisioning information extracted from the target provisioning package (e.g., a provisioning credential identifier, a share instance identifier, a device identifier, and a user identifier). In response, the external computing system 712, at 748, sends the provisioning system 710 the credential. In response, at 750, the provisioning system 710 sends a request to obtain a provisioning bundle, which will depend on the credential type. The provisioning bundle may include metadata, image files, and the like for presentation of the credential in the virtual wallet on the target provisioning device 708.In response, at 753, the external computing system 712 sends the provisioning batch to the provisioning system 710. Once the provisioning system 710 is receiving the provisioning batch, the provisioning system 710 may transmit a URL to the target provisioning device 708, at 754. In response, at 756, the target provisioning device 708 registers with the provisioning system 710 for transaction notification. A transaction notification may be implemented by the transaction processing system.
[0058] Continuing with box 726 in [Fig.7C], at 758, the provisioning system 710 registers for a transaction notification service with the external computing system 712. In some examples, the registration at 758 may be optional. For example, the registration at 758 may be implemented if the external computing system 712 supports providing notifications when transactions occur. In response, at 760, the external computing system 712 provides credential information including at least an authentication token and a settlement data element to the system provisioning system 710. At 762, the provisioning system 710 provides the credential information to the target provisioning device 708.
[0059] As shown herein, block 728 in [Fig.7C] represents a sequence for provisioning when the target provisioning device 708 is inside the circle of trust. In this example, at 764, which is implemented after 734 (outside blocks 726 and 728), the source provisioning device 706 sends the encrypted target provisioning package directly to the provisioning system 710. At 766, the provisioning system 710 decrypts the encrypted target provisioning package. At 768, the provisioning system 710 validates the policy from the target provisioning package. At 770, the provisioning system 710 stores the target provisioning package. At 772, the provisioning system 710 sends a push notification to the target provisioning device 708.In response, the target provisioning device 708 requests, at 774, and receives, at 776, provisioning information that includes sharing instance identifiers.
[0060] At this point, loop box 778 is implemented. The portion of loop box 778 in [Fig. 7C] includes 780 and 782 to 788. At 780, the target provisioning device 708 begins provisioning in the application by sharing a provisioning instance identifier with the provisioning system 710. At 782, the provisioning system 710 requests credential information, e.g., a provisioning credential that includes a provisioning credential identifier and a device identifier. 784 to 788 correspond, respectively, to 748 to 752 of [Fig. 7B]. Similarly, 790 to 798 in [Fig. 7D] correspond, respectively, to 754 to 762.
[0061] In some examples, when the user 702 selects a recipient (e.g., an email account identifier) to receive the credential, the credential may be linked to that recipient via a call made by the source provisioning device 706 with the provisioning system 710. This call may contain the credential identifier and the email account identifier of the recipient. The provisioning system 710 may follow this mapping and at the time of exchange ensures that the exchange device (e.g., the target provisioning device 708) is logged into an account on the cloud computing and storage system 206 associated with the email account identifier provided by the source provisioning device 706 at the time of linking.In this example, the provisioning system 710 may store the mapping between the sender and the recipient before exchange by the exchange device.
[0062] Alternatively, in some examples, credentials are not linked to an account of the recipient's cloud storage and computing system 206. at the time of sharing. The external computing system 712 (e.g., the system that issues the credential) may provide a credential identifier to the virtual wallet of the source provisioning device 706, which allows the user to send the credential using a messaging application and the messaging system 202 to anyone. Anyone with the credential identifier can use it to provision the credential in their virtual wallet. In some examples, the credential identifier may be tied to the first account of the cloud computing and storage system 206 that redeems it. In this way, it may be difficult for others to redeem the credential.
[0063] [Figs. 8A] through 8E illustrate a sequence diagram 800 showing exemplary processes for provisioning credentials for use on user devices, according to various examples. In particular, the sequence diagram 800 depicts processes for provisioning credentials, using a browser and a web application provided by a third party. For example, the sequence diagram 800 may correspond to a process by which a user provisions credit card credentials for her own user devices and / or for other user devices via a web page hosted by the bank that supports the credit card. In this example, the external computing system plays a more active role in authenticating the user devices.
[0064] As elements in the sequence diagram 800, [Figs. 8A]-8E include a browser 802 (e.g., a browser application on the source user device 106), an external computing system 804 (e.g., the issuing system 220), a web application 806 (e.g., a web application hosted by a provisioning system 808), the provisioning system 808 (e.g., the provisioning system 204), a target provisioning device 810 (e.g., the target user device 108), and another computing system 812 (e.g., the issuing system 220). As described herein, in some examples, the source device 106 does not include a secure element.
[0065] Beginning with [Fig.8A], at 814, the browser obtains a request to provision to a digital wallet. This may be received as user input received at a web page of the external computing system 804 presented at the source provisioning device. At 816, the browser 802 sends a request to the external computing system 804 requesting provisioning information including a provisioning target ID. In response, the external computing system 804, at 818, generates the provisioning target ID. At 820, the external computing system 804 creates a signed token (e.g., a JSON web token), 824. The token 824 identifies the external computing system 804 as the issuer. At 826, the external computing system 804 sends a notification to the browser 802. In response, at 828, the browser 802 sends a post to the web application 806.
[0066] Looking now at [Fig.8B], [Fig.8B] includes another box 830, which is implemented when the client ID associated with the browser 802 and the associated application support quick login. Quick login may allow the user to use her credentials for the web application 806 to log in at the browser 802. In some examples, this may be referred to as "Login with an entity." At 832, the web application 806 sends a message to the browser 802 to request login credentials. At 834, the user logs in with the entity, using the browser 802, which causes the browser 802, at 836, to redirect to the web application 806. If necessary, an authorization code 838 may be entered at the browser 802 to authorize the attempt to log in with the entity using the web application 806.At 840, the web application 806 requests, from the provisioning system 808, a list of devices using the authorization code, the request ID, and the client ID. In response to the request, the provisioning system 808, at 842, determines the entity ID and requests a target provisioning package based on the provisioning target ID from the external computing system 804 at 844.
[0067] Looking now at [Fig.8C], at 844, the external computing system 804 generates the target provisioning package 846. In some examples, at 844, the external computing system 804 may also share the target provisioning package 846 with the provisioning system 808. At 848, the provisioning system 808 generates a list of eligible devices, using the entity ID, the policy, and the product ID. In some examples, the list of eligible devices includes devices that may receive the credential. The devices may be associated with the account of the user who initiated the process represented by the sequence diagram 800, or may be associated with accounts of other users. At 850, the provisioning system 808 sends a list of devices with the web application 806.Using this information, the web application 806, at 852, provides a device selection page at the browser 802. The device selection page allows the user to select the devices from the list of devices that are to receive the credential. Thus, at 854, the user selects one or more devices from the device selection page presented at the browser 802. At 856, the selected devices are shared with the web application 806 and, at 858, the web application 806 shares the selected devices with the provisioning system 808.
[0068] Looking now at [Fig.8D], [Fig.8D] depicts a loop 860, which includes, at 862, the provisioning system 808 pushing a notification to the target provisioning device 810. The notification may include information indicating that an attempt is being made to provision a credential on the target provisioning device 810. At 864, the provisioning system 808 sends a confirmation message to the web application 806. At 866, the web application 806 redirects the browser 802 to the original state, e.g., before the login flow with an entity and device selection. For example, this may be a current web page of the bank or other entity associated with the credential. Steps 868, 870, and 872 may be implemented similarly to what is described with reference to steps 774, 776, and 780.At 868, for example, in response to the notification at 862, the target provisioning device 810 requests sharing instance identifiers from the provisioning system 808. In response, at 870, the provisioning system 808 provides a list to the target provisioning device 810 including the sharing instance identifiers. At 872, the target provisioning device 810 implements a new card verification eligibility with the provisioning system 808 using the sharing instance identifier and the device identifier. At 874, the provisioning system 808 requests the provisioning credential from the external computing system 804 using the provisioning credential identifier, derived from the target provisioning package 846.In response, at 876, the external computing system 804 provides credential data including the credential to the provisioning system 808. At 878, the provisioning system 808 implements a network verification of the card associated with the credential by communicating with the other computing system 812. In response, at 880, the other computing system 812 sends a confirmation message to the provisioning system 808. At 882, the provisioning system 808 confirms with the target provisioning device 810 that the credential is available for use.
[0069] [Fig. 9] illustrates a descriptive diagram showing an exemplary process 900 for provisioning a credential for use on a second user device in response to a request from a first user device, according to at least one example. The process 900 may be implemented by the service provider 104 and in particular the provisioning system 204 of the service provider 104. The process 900 may relate to an in-application provisioning process such as, for example, described with reference to [Fig. 7A]-7D. For example, using the process 900, a user on a first device may cause the provisioning of one or more credentials on second devices. Second devices may have account information shared with the first device or may be independent.
[0070] Process 900 begins at 902 with provisioning system 204 ([Fig.2]) receiving a first request from a first user device (e.g., a source user device). The first request may be associated with a provisioning request to provision a credential on a second user device (e.g., a target user device). In some examples, a second user account of the second user device is excluded from a set of trusted accounts managed by a user account of the first user device. In some examples, a second user account of the second user device is included in a set of trusted accounts managed by a user account of the first user device.
[0071] At 904, the process 900 includes providing by the provisioning system 204 a nonce and a provisioning certificate chain to the first user device. The nonce and the provisioning certificate chain may be shared with the first user device in response to the first request received at 902.
[0072] At 906, process 900 includes receiving by provisioning system 204 an encrypted target provisioning package from the first user device. The encrypted target provisioning package may include the nonce and provisioning information for provisioning the credential for use on the second user device. In some examples, receiving the encrypted target provisioning package may include receiving the encrypted target provisioning package via an instant messaging system (e.g., messaging system 202) and an associated messaging application on the user device.
[0073] At 908, the process 900 includes extracting by the provisioning system 204 at least a portion of the provisioning information from the encrypted target provisioning package. In some examples, extracting at least the portion of the provisioning information may include extracting at least one of a provisioning credential identifier, a sharing instance identifier, a user device identifier identifying the second user device, or a user identifier identifying a user account associated with the second user device.In this example, the second request may include at least one of a provisioning credential identifier, the sharing instance identifier, the user device identifier identifying the second user device, or the user identifier identifying the user account associated with the second user device.
[0074] In some examples, prior to extracting the provisioning information, the process 900 may include the provisioning system 204 decrypting the encrypted target provisioning package.
[0075] At 910, the process 900 includes provisioning by the provisioning system 204 the credential for use on the second user device. This may be based at least in part on the portion of the provisioning information retrieved at 908. In some examples, the provisioning information may include a provisioning policy. In this example, provisioning the credential for use on the second device may be based at least in part on validation of the provisioning policy. In some examples, provisioning the credential for use on the second user device may include provisioning without receiving a provisioning request from the second user device.For example, provisioning on the second user device may be implemented automatically and / or without the second user device independently requesting such provisioning from the provisioning system 204.
[0076] In some examples, the process 900 may further include sending by the provisioning system 204, to an external computing system (e.g., an issuing system 220 ([Fig.2])), a second request for credential information corresponding to the credential. The second request may include the portion of the provisioning information retrieved previously. In this example, the provisioning of the credential for use on the second user device at 910 may further be based at least in part on the credential information received from the external computing system.
[0077] [Fig. 10] illustrates a descriptive diagram showing an exemplary process 1000 for provisioning a credential for use on a second user device in response to a request from a first user device, according to at least one example. The process 1000 may be implemented by the service provider 104 and in particular the provisioning system 204 of the service provider 104. The process 1000 may relate to an online provisioning process such as, for example, described with reference to [Fig. 8A] to 8E. For example, using the process 1000, a user on a first device may, from a browser using a web application, cause provisioning of one or more credentials to second devices. The second devices may have account information shared with the first device or may be independent.
[0078] The process 1000 begins at 1002 with the provisioning system 204 ([Fig.2]) receiving an indication that a user account successfully logged into a web application associated with the provisioning system. In some examples, the web application is hosted by a cloud computing and storage system (e.g., 206) associated with the provisioning system.
[0079] At 1004, the process 1000 includes receiving by the provisioning system 204 an encrypted target provisioning package from an external computing system. The encrypted target provisioning package may include provisioning information for provisioning a credential for use on a user device associated with the user account. In some examples, the target provisioning package is generated based at least in part on information from the web application obtained when the user account successfully logged into the web application.
[0080] At 1006, the process 1000 includes determining by the provisioning system 204 a list of user devices that may receive the credential based at least in part on the provisioning information. Individual user devices from the list of user devices may be associated with the user account. In some examples, at least one user device from the list of user devices is associated with a different user account.
[0081] At 1008, the process 1000 includes receiving by the provisioning system 204 a selection of a particular user device from the list of user devices. In some examples, the process 1000 may further include sending the list of devices to the web application. The web application may be configured to provide a device selection web page at the first user device that includes the list of user devices.
[0082] At 1010, the process 1000 includes provisioning by the provisioning system 204 the credential for use on the particular user device based at least in part on the provisioning information. In some examples, provisioning the credential for use on the particular user device may include exchanging sharing information (e.g., sharing instance information) with the particular user device, and exchanging credential information with the external computing system.
[0083] [Fig. 11] illustrates a descriptive diagram showing an example process 1100 for provisioning a credential for use on a second user device in response to a request from a first user device, according to at least one example. The process 1100 may be implemented by the service provider 104. The process 1100 may relate to a process provisioning in the application such as, for example, described with reference to [Fig.7A] to 7D.
[0084] Process 1100 begins at 1102 by receiving, via a messaging system 202 ([Fig.2]), a request to provision a credential for use on a second device. The request may be received from a first user device. The request may include an encrypted target provisioning package that includes provisioning information. In some examples, the encrypted target provisioning package is received via a messaging application on the second user device. In some examples, process 1100 may further include providing a nonce and a provisioning certificate to the first user device. In this example, the first user device may be configured to generate the target provisioning package and use the nonce and / or the provisioning certificate to encrypt the target provisioning package.
[0085] At 1104, the process 1100 includes validating, using the messaging system 202, a user account associated with the second device. The validation may be based at least in part on provisioning information in the encrypted target provisioning package.
[0086] At 1106, process 1100 includes storing, using a cloud storage and computing system 206 ([Fig.2]), the target provisioning package in a remote storage location associated with the user account.
[0087] At 1108, the process 1100 includes validating, using a provisioning system 204 ([Fig.2]), the credential information associated with the credential. The validation of the credential information may be based at least in part on provisioning information in the target provisioning package. In some examples, the process 1100 may further include receiving the credential information from the second user device. In this example, the credential information may include the nonce.
[0088] At 1110, the process 1100 includes provisioning the credential for use on the second user device based at least in part on validation of the credential information. This may be implemented by the provisioning system 204 and / or the second user device. In some examples, the user account is associated with the second user device and is included in a set of trusted accounts managed by a user account associated with the first user device. In this example, provisioning the credential for use on the second user device may be implemented without receiving user input from the user account of the second user device.
[0089] [Fig. 12] illustrates an exemplary architecture or environment 1200 configured to implement the techniques described herein, according to at least one example. In some examples, the exemplary architecture 1200 may be further configured to enable a user device 1206 and a service provider computer 1202 to share information. The service provider computer 1202 is an example of the service provider 104, the delivery system 220, and the other computing system 812. The user device 1206 is an example of the user devices 106 and 108. In some examples, the devices may be connected via one or more networks 1208 (e.g., via Bluetooth, WiFi, the Internet, or the like). In some examples, the service provider computer 1202 may be configured to implement at least some of the techniques described herein with reference to the user device 1206.
[0090] In some examples, the networks 1208 may include any one or a combination of many different types of networks, such as cable networks, the Internet, wireless networks, cellular networks, satellite networks, other private and / or public networks, or any combination thereof. While the illustrated example depicts the user device 1206 accessing the service provider computer 1202 via the networks 1208, the described techniques may also apply in cases where the user device 1206 interacts with the service provider computer 1202 over a landline telephone line, via a payphone, or in any other manner. It should also be noted that the described techniques may apply in other client / server arrangements (e.g., set-top boxes, etc.), as well as in non-client / server arrangements (e.g., locally stored applications, peer-to-peer setups, etc.).
[0091] As indicated above, the user device 1206 may be any type of computing device such as, but not limited to, a mobile phone, a smartphone, a personal digital assistant (PDA), a laptop computer, a desktop computer, a thin client device, a tablet, a wearable device such as a smart watch, or the like. In some examples, the user device 1206 may be in communication with the service provider computer 1202 via the network 1208, or via other network connections.
[0092] In an illustrative configuration, the user device 1206 may include at least one memory 1214 and one or more processing units (or processor(s)) 1216. The processor(s) 1216 may be implemented, as the case may be, in hardware, computer-executable instructions, firmware, or combinations thereof. The computer-executable instruction or firmware implementations of the processor(s) 1216 may include computer-executable or machine-executable instructions written in any suitable programming language to implement the various functions described. The user device 1206 may also include geolocation devices (e.g., a global positioning system (GPS) device or the like) to provide and / or record geographic location information associated with the user device 1206.
[0093] The memory 1214 may store program instructions that may be loaded and executed on the processor(s) 1216, as well as data generated during the execution of those programs. Depending on the configuration and type of the user device 1206, the memory 1214 may be volatile (such as random access memory (RAM)) and / or non-volatile (such as read only memory (ROM), flash memory, etc.).The user device 1206 may also include additional removable storage and / or non-removable storage 1226 including, but not limited to, magnetic storage, optical disks, and / or tape storage. Disk drives and their associated non-transitory computer-readable media may provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the computing devices. In some implementations, the memory 1214 may include multiple different types of memory, such as static random access memory (SRAM), dynamic random access memory (DRAM), or ROM. While the volatile memory described herein may be referred to as RAM, any volatile memory that would not retain data stored therein once disconnected from a host and / or power supply would be suitable.
[0094] Memory 1214 and additional storage 1226, both removable and non-removable, are all examples of non-transitory computer-readable storage media. For example, non-transitory computer-readable storage media may include volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Memory 1214 and additional storage 1226 are both examples of non-transitory computer storage media.Additional types of computer storage media that may be present in user device 1206 may include, but are not limited to, phase change RAM (PRAM), SRAM, DRAM, RAM, ROM, electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital video disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, . magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and that can be accessed by the user device 1206. Combinations of any of the foregoing are also to be included within the scope of non-transitory computer-readable storage media. Alternatively, computer-readable communication media may include computer-readable instructions, program modules, or other data transmitted within a data signal, such as a carrier wave, or other transmission. However, as used herein, computer-readable storage media does not include computer-readable communication media.
[0095] The user device 1206 may also contain one or more communication connections 1228 that allow the user device 1206 to communicate with a database, another computing device or server, user terminals, and / or other devices via the network 1208. The user device 1206 may also include one or more I / O devices 1230, such as a keyboard, mouse, stylus, voice input device, touchscreen input device, display, speakers, printer, etc.
[0096] Regarding the contents of memory 1214 in more detail, memory 1214 may include an operating system 1212 and / or one or more application programs or services for implementing the functionality disclosed herein such as applications 1211 (e.g., digital wallet, third-party applications, browser application, etc.). In some examples, service provider computer 1202 may also include a healthcare application for implementing techniques similar to those described with reference to user device 1206. Similarly, at least some techniques described with reference to service provider computer 1202 may be implemented by user device 1206.
[0097] The service provider computer 1202 may also be any type of computing device such as, but not limited to, a collection of virtual or "cloud" computing resources, a remote server, a mobile phone, a smartphone, a personal digital assistant, a laptop computer, a desktop computer, a thin client device, a tablet, a wearable device, a server computer, a virtual machine instance, etc. In some examples, the service provider computer 1202 may be in communication with the user device 1206 via the network 1208, or via other network connections.
[0098] In an illustrative configuration, the service provider computer 1202 may include at least one memory 1242 and one or more processing units (or processor(s)) 1244. The processor(s) 1244 may be implemented depending on the situation in hardware, computer-executable instructions, firmware, or combinations thereof. The computer-executable instruction or firmware implementations of the processor(s) 1244 may include computer-executable or machine-executable instructions written in any suitable programming language to implement the various functions described.
[0099] The memory 1242 may store program instructions that may be loaded and executed on the processor(s) 1244, as well as data generated during execution of those programs. Depending on the configuration and type of service provider computer 1202, the memory 1242 may be volatile (such as RAM) and / or non-volatile (such as ROM, flash memory, etc.). The service provider computer 1202 may also include additional removable storage and / or non-removable storage 1246 including, but not limited to, magnetic storage, optical disks, and / or tape storage. The disk drives and their associated non-transitory computer-readable media may provide non-volatile storage of computer-readable instructions, data structures, program modules, and other data for the computing devices.In some implementations, memory 1242 may include multiple different types of memory, such as SRAM, DRAM, or ROM. While the volatile memory described herein may be referred to as RAM, any volatile memory that would not retain data stored therein once disconnected from a host and / or power supply would be suitable. Memory 1242 and additional storage 1246, both removable and non-removable, are each additional examples of non-transitory computer-readable storage media.
[0100] The service provider computer 1202 may also contain one or more communication connections 1248 that allow the service provider computer 1202 to communicate with a database, another computing device or server, user terminals, and / or other devices via the network 1208. The service provider computer 1202 may also include one or more I / O devices 1250, such as a keyboard, mouse, stylus, voice input device, touchscreen input device, display, speakers, printer, etc.
[0101] Regarding the contents of memory 1242 in more detail, memory 1242 may include an operating system 1252 and / or one or more application programs or services for implementing the functionalities disclosed herein including one or more provisioning engines 1241 (e.g., provisioning service transport 210, provisioning service 224, transaction processing service 226, and / or authentication service 230).
[0102] The various examples may further be implemented in a wide variety of operating environments, which in some cases may include one or more user computers, computing devices, or processing devices that may be used to operate any of a number of applications. User or client devices may include any of a number of general-purpose personal computers, such as desktop or laptop computers running a standard operating system, as well as cellular, wireless, and portable devices running mobile software and capable of supporting a number of networking and messaging protocols.Such a system may also include a number of workstations running any of a variety of commercially available operating systems and other known applications for purposes such as database development and management. These devices may also include other electronic devices, such as dummy terminals, thin clients, gaming systems, and other devices capable of communicating via a network.
[0103] Most examples utilize at least one network that would be familiar to those skilled in the art to support communications using any of a variety of commercially available protocols, such as TCP / IP, OSI, FTP, UPnP, NFS, CIFS, and AppleTalk. The network may be, for example, a local area network, a wide area network, a virtual private network, the Internet, an intranet, an extranet, a public switched telephone network, an infrared network, a wireless network, and any combination thereof.
[0104] In examples using a network server, the network server may run any of a variety of server or middle-tier applications, including HTTP servers, FTP servers, CGI servers, data servers, Java servers, and business application servers. The server(s) may also be capable of executing programs or scripts in response to requests from user devices, for example, by executing one or more applications that may be implemented as one or more scripts or programs written in any programming language, such as Java®, C, C#, or C++, or any scripting language, such as Perl, Python, or TCL, as well as combinations thereof. The server(s) may also include database servers, including without limitation those commercially available from Oracle®, Microsoft®, Sybase®, and IBM®.
[0105] The environment may include a variety of data banks and other memory and storage media as discussed previously. These may be located in a variety of locations, such as on a storage medium local to (and / or located within) one or more of the computers or remote from any or all of the computers across the network. In one particular set of examples, the information may be located in a storage area network (SAN) familiar to those skilled in the art. Similarly, any files necessary to implement the functions assigned to the computers, servers, or other network devices may be stored locally and / or remotely, as appropriate.When a system includes computerized devices, each of these devices may include hardware elements that may be electrically coupled via a bus, the elements including, for example, at least one central processing unit (CPU), at least one input device (e.g., a mouse, keyboard, controller, touchscreen, or keypad), and at least one output device (e.g., a display device, printer, or speaker). Such a system may also include one or more storage devices, such as disk drives, optical storage devices, and solid-state storage devices such as RAM or ROM, as well as removable media devices, memory cards, flash cards, etc.
[0106] Such devices may also include a computer-readable storage media reader, a communications device (e.g., a modem, a network card (wireless or wired), an infrared communication device, etc.), and a working memory as described above. The computer-readable storage media reader may be connected to, or configured to receive, non-transitory computer-readable storage media, representing remote, local, fixed, and / or removable storage devices and storage media for temporarily and / or more permanently containing, storing, transmitting, and retrieving computer-readable information.The system and various devices also typically include a number of software applications, modules, services, or other elements located within at least one working memory device, including an operating system and application programs, such as a client application or a browser. It should be kept in mind that alternative examples may have many variations from what is described above. For example, custom hardware could also be used and / or particular elements could be implemented in hardware, software (including portable software, such as applets), or both. In addition, connection to other computing devices such as network input / output devices may be employed.
[0107] Non-transitory storage media and computer-readable media for containing code, or portions thereof, may include any suitable medium known or used in the art, including storage media, such as, but not limited to, volatile and non-volatile, removable and non-removable media, implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data, including RAM, ROM, EEPROM, flash memory, or other memory technology, CD-ROM, DVD, or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to store the desired information and that can be accessed by a system device.Based at least in part on the disclosure and teachings provided herein, one of ordinary skill in the art will appreciate alternative ways and / or methods for implementing the various examples.
[0108] Thus, the description and drawings are to be considered by way of illustration rather than limitation. It will be apparent, however, that various modifications and changes may be made therein without departing from the broader spirit and scope of the disclosure as set forth in the claims.
[0109] Other variations are within the spirit of the present disclosure. Thus, although the disclosed techniques are susceptible of various modifications and alternative constructions, certain illustrated examples thereof are shown in the drawings and have been described in detail above. It should be understood, however, that there is no intention to limit the disclosure to the specific form or forms disclosed, but rather, the intention is to cover all modifications, alternative constructions, and equivalents falling within the spirit and scope of the disclosure, as defined in the appended claims.
[0110] The use of the terms "a," "an," "the," and "the" and similar referents in the context of describing the disclosed examples (especially in the context of the claims that follow) should be interpreted as covering both the singular and the plural, unless otherwise indicated herein or an obvious contradiction dictated by the context. The terms "comprising," "having," "including," and "containing" should be interpreted as relatively vague terms (e.g., meaning "including, but not limited to," ) unless otherwise indicated. The term "connected" should be considered as contained partially or entirely within, attached to, or joined together, even if there is something in between. The citation of range of values herein is only intended to serve as a shorthand method of individually referring to each separate value falling within the range, unless otherwise indicated. herein, and each separate value is incorporated in the specification as if individually recited herein. All methods described herein may be practiced in any proper order unless otherwise indicated herein or the context otherwise dictates. The use of any example, or exemplary wording (e.g., "such as") provided herein, is intended only to better highlight examples of the disclosure and is not a limitation on the scope of the disclosure unless otherwise claimed. No wording in the specification should be construed to indicate any unclaimed element as essential to the practice of the disclosure.
[0111] Disjunctive language such as the phrase "at least one of X, Y, or Z," unless specifically indicated otherwise, is otherwise understood in the context as it is used generally to convey that an item, term, etc. may be either X, Y, or Z, or any combination thereof (e.g., X, Y, and / or Z). Thus, such disjunctive language is not intended to, and should not, imply that some examples require that at least one of X, at least one of Y, or at least one of Z be present.
[0112] Preferred examples of the present disclosure are described herein, including the best mode known to the inventors for making the disclosure. Variations of these preferred examples may become apparent to those skilled in the art upon reading the foregoing description. The inventors expect that skilled artisans will use such variations, if any, and the inventors anticipate that the disclosure will be practiced other than as specifically described herein. Thus, this disclosure includes all modifications and equivalents of the subject matter described in the claims appended hereto, as permitted by applicable law. In addition, any combination of the foregoing, in all their possible variations, is encompassed by the disclosure, unless otherwise indicated herein or otherwise clearly inconsistent with the context.
[0113] As described above, one aspect of the present technology is the collection and use of data available from various sources to provide a complete and comprehensive window into a user's personal health record. The present disclosure contemplates that, in some instances, the collected data may include personally identifiable information (PII) that uniquely identifies or can be used to contact or locate a specific individual. Such personal data may include demographic data, location data, phone numbers, email addresses, Twitter handles, home addresses, data or records relating to a user's health or fitness (e.g., vital sign measurements, medication information, exercise information), date of birth, medical records data or any other identifying or personal or health information.
[0114] The present disclosure recognizes that the use of such personal information data, in current technology, may be used to benefit users. For example, the personal information data may be used to provide enhancements to a user's personal medical record. In addition, other uses of the personal information data that benefit the user are also contemplated by the present disclosure. For example, health and fitness data may be used to provide understandings of a user's overall well-being, or be used as positive feedback for individuals using the technology to achieve wellness goals.
[0115] The present disclosure contemplates that entities responsible for the collection, analysis, disclosure, transfer, storage, or other use of such personal information data will comply with well-established privacy policies and / or privacy practices. In particular, such entities must consistently implement and utilize privacy policies and practices that are generally recognized as meeting, or exceeding, industry or government requirements for keeping personal information data private and secure. Such policies must be readily accessible by users, and must be updated as the collection and / or use of the data changes.Users' personal information must be collected for legitimate and reasonable uses of the entity and must not be shared or sold outside of these legitimate uses. Furthermore, such collection / sharing must be done after obtaining informed consent from users. In addition, such entities must consider taking all necessary measures to safeguard and secure access to such personal information data and ensure that others with access to such data adhere to their privacy policies and procedures. In addition, such entities may submit to a third-party assessment to certify their adherence to widely accepted privacy policies and practices.In addition, policies and practices must be tailored to the particular types of personal information data being collected and / or accessed and adapted to applicable laws and standards, including jurisdiction-specific considerations. For example, in the United States, the collection of or access to certain health data may be governed by federal and / or state laws, such as the Health Insurance Portability and Accountability Act (HIPAA); while health data in other countries may be subject to . to other regulations and policies and must be treated accordingly. As a result, different privacy practices must be maintained for different types of personal data in each country.
[0116] Notwithstanding the foregoing, the present disclosure also contemplates embodiments in which users selectively block the use of, or access to, personal information data. In other words, the present disclosure contemplates that hardware and / or software elements may be provided to prevent or block access to such personal information data. For example, in the case of ad serving services or other services relating to medical records management, the present technology may be configured to allow users to choose to "opt in" or "opt out" of participating in the collection of personal information data when registering for services or at any time thereafter.In addition to providing “opt-in” and “opt-out” options, this disclosure contemplates the provision of notifications regarding access to or use of personal information. For example, a user may be notified upon downloading an application that their personal data will be accessible, and then be reminded again just before the application accesses their personal data.
[0117] In addition, the present disclosure is intended to ensure that personal information data is managed and processed in a manner that minimizes the risk of unintended or unauthorized access or use. Risk may be minimized by limiting data collection and deleting data when no longer needed. In addition, and where appropriate, including in certain health-related applications, de-identification of data may be used to protect a user's privacy. De-identification may be facilitated, where appropriate, by removing specific identifiers (e.g., date of birth, etc.), controlling the amount or specificity of data stored (e.g., collecting location data at a city level rather than an address level), controlling how data is stored (e.g., aggregating data across users), and / or by other methods.
[0118] Therefore, although the present disclosure broadly covers the use of personal information data to implement one or more various disclosed embodiments, the present disclosure also contemplates that the various embodiments may also be implemented without the need to access such personal information data. That is, the various embodiments of the present technology are not rendered inoperable due to the absence of all or part of such personal information data.
Claims
Claims
1. 1 Computer-readable medium(s) comprising computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising: in response to a first request from a first user device, providing a nonce and a provisioning certificate to the first user device, the nonce and the provisioning certificate relating to a provisioning request initiated by the first user device for provisioning a credential for use on a second user device, receiving an encrypted target provisioning package from the first user device, a target provisioning package being generated using the nonce and the provisioning certificate,and the nonce being used to encrypt the target provisioning package to define the encrypted target provisioning package, the encrypted target provisioning package comprising the nonce and provisioning information for provisioning the credential for use on the second user device; extracting at least a portion of the provisioning information from the encrypted target provisioning package; and provisioning the credential for use on the second user device based at least in part on the portion of the provisioning information.,
2. 2 The computer-readable medium of claim 1, wherein the computer-executable instructions further cause the processor(s) to perform operations including sending, to an external computing system, a second request for credential information corresponding to the credential, the second request including the portion of the provisioning information, and wherein the provisioning of the credential for use on the second user device is further based at least in part on the credential information.
3. 3 Computer-readable medium(s) according to claim 2, wherein the external computer system comprises an issuing system which issued the credential.
4. 4 The computer-readable medium of claim 2, wherein retrieving at least the portion of the provisioning information comprises retrieving at least one of a provisioning credential identifier, a sharing instance identifier, a user device identifier identifying the second user device, or a user identifier identifying a user account associated with the second user device, and wherein the second request comprises at least one of the provisioning credential identifier, the sharing instance identifier, the user device identifier identifying the second user device, or the user identifier identifying the user account associated with the second user device.
5. 5 Computer-readable medium(s) according to claim 2, wherein a second user account of the second user device is excluded from a set of trusted accounts managed by a user account of the first user device.
6. 6 The computer-readable medium of claim 1, wherein a second user account of the second user device is included in a set of trusted accounts managed by a user account of the first user device.
7. 7 The computer-readable medium(s) of claim 1, wherein the computer-executable instructions further cause the processor(s) to perform operations including decrypting the encrypted target provisioning package.
8. 8 The computer-readable medium of claim 1, wherein the provisioning information comprises a provisioning policy, and wherein provisioning of the credential for use on the second user device is based at least in part on validation of the provisioning policy.
9. 9 Computer-readable medium(s) according to claim 1, wherein receiving the encrypted target provisioning package includes receiving the encrypted target provisioning package via an instant messaging system.
10. 10 The computer-readable medium of claim 1, wherein provisioning the credential for use on the second user device comprises provisioning without receiving a provisioning request from the second user device.
11. 11 A system, comprising: a memory comprising computer-executable instructions; and a processor configured to access the memory and execute the computer-executable instructions to at least: receive an indication that a user account has successfully logged into a web application associated with a provisioning system; receive an encrypted target provisioning package from an external computing system, the encrypted target provisioning package comprising provisioning information for provisioning a credential for use on a user device associated with the user account, the encrypted target provisioning package being generated at least in part based on information from the web application obtained when the user account has successfully logged into the web application;determining a list of user devices eligible to receive the credential based at least in part on the provisioning information, wherein individual user devices in the list of user devices are associated with the user account; receiving a selection of a particular user device from the list of user devices; and provisioning the credential for use on the particular user device based at least in part on the provisioning information.;
12. 12 The system of claim 11, wherein the processor is further configured to access memory and execute the computer-executable instructions to at least send the list of user devices to the web application, the web application being configured to provide a device selection web page that includes the user device list.
13. 13 The system of claim 11, wherein provisioning the credential for use on the particular user device comprises: exchanging sharing information with the particular user device; and exchanging credential information with the external computing system.
14. 14 The system of claim 11, wherein at least one user device in the list of user devices is associated with a different user account.
15. 15 The system of claim 11, wherein the web application is hosted by a cloud storage and computing system associated with the provisioning system.
16. 16 A computer-implemented method, comprising: providing a nonce and a provisioning certificate to a first user device, the first user device configured to generate a target provisioning package using the nonce and the provisioning certificate, and using the nonce to encrypt the target provisioning package; receiving, via a messaging system and from the first user device, a request to provision a credential for use on a second user device, the request comprising the encrypted target provisioning package that includes provisioning information; validating, using the messaging system, a user account associated with the second device based at least in part on the provisioning information included in the encrypted target provisioning package;storing, using a cloud storage and computing system, the target provisioning package in a remote storage location associated with the user account; validating, using a provisioning system, the credential information associated with the credential based at least in part on the provisioning information included in the encrypted target provisioning package; and; provisioning the credential for use on the second user device based at least in part on validation of the credential information.
17. 17 The computer-implemented method of claim 16, further comprising receiving the credential information from the second user device, and wherein the credential information comprises the nonce.
18. 18 The computer-implemented method of claim 16, wherein the user account associated with the second user device is included in a set of trusted accounts managed by a user account associated with the first user device, and wherein provisioning the credential for use on the second user device is implemented without receiving user input from the user account of the second user device.