Secure sharing of identity verification information

FR3162089A1Pending Publication Date: 2025-11-14APPLE INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2025004977
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Priority Date
2020-05-29
Filing Date
2025-05-12
Publication Date
2025-11-14

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A first user device is used to request the provisioning of a secure credential on a second user device. The process includes: the first user device receiving a notification from a provisioning system regarding the provisioning of a provisioning item; in response to the notification and a provisioning information request from the provisioning system, receiving the provisioning information, including a Share Instance ID; initiating a provisioning sequence in an application using the Share Instance ID; and, upon completion of the provisioning sequence in an application, registering with the provisioning system for transaction notifications concerning the provisioning item. Figure 1 for the abstract
Need to check novelty before this filing date? Find Prior Art

Claims

to, at the very least, produce a graphical representation of the proof of identity in a user interface of the first user device

17. 17 A computer-implemented method comprising: receiving, on a first user device and from a provisioning system, a notification associated with the provisioning of a provisioning item; in response to receiving the notification and a request for provisioning information from the provisioning system, receiving the provisioning information including a share instance identifier; starting a provisioning sequence in an application, using the share instance identifier; and upon completion of the provisioning sequence in an application, registering with the provisioning system for transaction notifications concerning the provisioning item.

18. 18 The computer-implemented method of claim 17, further comprising, prior to receipt of the notification associated with provisioning the provisioning element: receiving, from a second user device, an encrypted target provisioning package configured to provision the provisioning element on the first user device; and delivering the encrypted target provisioning package to the provisioning system, to enable provisioning the provisioning element on the first user device.

19. 19 The computer-implemented method of claim 18, wherein the encrypted target provisioning package includes the sharing instance identifier.

20. The computer-implemented method of claim 18, wherein the encrypted target provisioning package is generated using a provisioning certification, and encrypted using a papal nuncio. [Fig. 2] 200 ,_________v_______ Device USER ~~ APPLICATION(S) 212 H User device APPLICATION(S) 214 ISSUING SYSTEM 220 DATABASE 232 OF ACCOUNTS Secure element 216 ELEMENT SECURE 218 Credential service 224 [Fig. 3] ADD 3 PASSES TO WALLET A guest with an entry pass can enter using a phone or watch. [Fig. 5] [Fig. 6] 330 Use centered pass To use an ENTRY PASS, HOLD THE PHONE OR WATCH ON THE READER. THIS WILL WORK AUTOMATICALLY. 332 Add now IN THE WALLET [Fig. 7A] [Fig. 7B] I deliver* application 700 Encrypted provisioning target - F encrypt { ' target certificate of । 734 prqvisionhgmeul} ait [Non-circle of trust, j Cibîe de [ provPstonnement i i encrypted I 730 726 I Provisioning = onrement in II Provisioning (target of I i encrypted provisioning) । decipher target del1 provision ne ment encryptée!._____| extract tdsntsficateur de' “l proof of identity of 1. | provisionneroent^----1 extract Identifier | sharing instance'^} 732 734 736 738 754 [Fig. 7C] 728 extract T-configuration identifier] I. Validate provisioning policy 746 750 752 740 Obtain proof of identity of provisioning identifier; proof of identity of provisioning, Instance identifier i of sharing. Device identifier, User identifier^ j proof of card} ■ r (obtain early advance notice based on the type of identity documents) ' URL pass J । Register for a service । | transaction notification । supply batch 756 $s? iroprovisioningj (Authentication token, Media settlement) [Circle of Trust] I [; PUÇLIER / targeted foumier of । promonnemsnt pcussée{ Target of, will provide encrypted} decrypt encrypted provisioning target I Validate policy i Store {target of provisioning i Send push notification I to a recipient device f GET!Ri!dLHicalëure | । of sharing instance ' [dentfiicateuis of sharing instance!} Icog) In the i application Provisioning( i of M sharing instance) । 782 784 786 788 Register for a transaction notification service [Authentication token, Media settlement). 762 764 obtain supply batch 66 780 Obtain proof of identity for provisioning (identity card) <jr de justificatif d'identité de provisionne ment,Ide^ Supporting identification documents {card fields} '770 778 Supply batch 758 ûâ 760 [Fig. 7D] । t______________________ Device d« H Device de provïswnernejif I provisionnèrent source- 7Qg | | obîe 7Qg Provisioning System II _____________I External computer system 712 Browser 802 External computer system %4 Web application Provisioning System 938 800 _____-______-_____ Target pro-disoning device 810 Other computer system&l2 |1]Provision 1 §14 $towards wallet^ / i i]2]obtain1D target provisioningO ! 1 . . |-. ! Œjûenerer ID ciole de provisionnément. 1 « 816 818 [4]create signed JWT •820 “iss”: “Web Transmitter”, "sub": "Customer ID", vaud”; “httpsA\payweb.com”. “exp”:1364293137871, “ial”:1364293137871. “jti”: “provisioned target ID” 824 [5)302 / payweb^ush 826 Token: JWT URL redirect: XXXXX Status: 3546464664 [6] POST / payweb / Push ---->^ / ■'828 I: I !■ L : [Fig. 8B] Supply system \ / 800 aË? Td client supports fast connection] [7J302 Get / id. URL entity7aut:payY,eb -832 [8] Connection with entity ' „ ¢- _ _— ---- 834 (&]redirect!on to URL [Fig. 8C] State code authorization [Browser 802] 838 844 844 Entity connection: Extent: type of response Pay: client ID code: URL redirectionTopay: Payweb status: 235655761 ^836 840 t [1 Ojobtenir liste de dispositifs । ï (Authorization Code. * ' ©request, icL.client); [UJget ID entityQ î [12]OBTAIN.'cib!&ds provisioning (SG target provisioning) 842 [13]generate target of P^visionnernerit [Device for provisioning-L target 810 800 Targeted provisionally "Provisioning Identity Justification Identifier"; ©Provisioning Identity Justification, "Creation Date": 156658211 "Extensive provisioning policy" apolitical, product_id: 2345 or card configuration, ID fpan 2345 846 [î4]0bienir list of eligible devices (entity ID, policy, IDjxoduili 848 [15]List of devices 850 [17]sètecüonner des dispositifs [16] Device selection page । - — _i _^ 4.^852 854 [18]List of selected devices [19]List of selected devices 858 [Fig. 8D] Browser [21J 200 [22]redirect to web issuer with original state 866 1 [23]OBTAINING flutter filters [ ! sharing instance | P4] | List (identifiers) (sharing instance) 868 [25] | 1. Obtain proof of identity of 1. Provision of payment (identifier) i sharing instance, i (Device identifier) ​​i ^r?? [Fig. 8E] [26] Provisioning Identity Credential {Provisioning Identity Credential Identifier} 874 [27]{Identity document data} i 4^876 System 870 800 Provisioning system he 878—U____ i t 880-x^---. i. 882 -q____ I: I hf li And ________________________________f Provisioning system Target provisioning device 810. Other computer system \ 812 z [28]Card network verification) ---------------------------------------------------------i--------------------------------------------------------------- P9J200; ------------ 130]..... J ------ tt 1 E tt E E____________________________________ Device of I target provisioning 810 | Other computer system 812 [Fig. 9] 9 / n 1000 1100