Appliance Token Provisioning for Secure Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current smart appliances rely on users' financial instruments for transactions, exposing financial information and being unsuitable for shared or non-owner appliances, such as rental cars, and lack autonomy in making purchases.
Innovation Solution
Issuing original account identifiers to appliances, provisioning device tokens, and associating user account identifiers to enable transactions without exposing users' financial information, allowing appliances to conduct transactions independently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the owner's financial instrument (credit card) is used for appliance transactions, then the appliance can conduct transactions, but the owner's financial information is exposed across multiple appliances and merchants
Solution Approach 1:
The patent introduces a token as an intermediary that sits between the appliance and the owner's financial instrument. The token contains encrypted references to the financial account but not the actual account details. When a transaction occurs, the token is used instead of the credit card number, preventing direct exposure of financial information while still enabling payment processing. The token acts as a mediator that preserves transaction capability without compromising security.
Solution Approach 2:
The patent creates a token copy that represents the financial instrument without containing the actual sensitive data. The token is a simplified representation that can be used for transactions but cannot be used to reconstruct the original financial account information. This copying approach allows the appliance to have a usable payment credential while the original sensitive information remains protected.
2Productivity
If the owner's PAN is provisioned on the appliance, then transactions can be authorized, but the model is not suitable for shared appliances or rental scenarios
Solution Approach 1:
The patent segments the financial instrument association by creating separate tokens for different appliances rather than provisioning the owner's PAN on each device. Each appliance receives its own token that is linked to the financial account through the token vault, allowing multiple appliances to be associated with a single financial instrument without exposing the PAN on each device. This segmentation enables shared and rental scenarios where multiple users can have access to different appliances.
Solution Approach 2:
The token system provides universal functionality across different appliances and ownership models. A single financial instrument can support multiple appliances through the token vault, and the same system works for owned, shared, and rental appliances. The token acts as a universal credential that adapts to different ownership scenarios without requiring changes to the underlying financial account structure.
3Ease of operation
If the appliance uses the owner's financial instrument, then transactions can be conducted, but the appliance lacks autonomous decision-making ability
Solution Approach 1:
The patent implements preliminary action by requiring owner authorization before the appliance can conduct transactions autonomously. The owner pre-approves transaction parameters such as spending limits, merchant categories, and time windows. The token is provisioned with these pre-set constraints, allowing the appliance to make autonomous decisions within authorized boundaries without requiring real-time owner approval for each transaction.
Solution Approach 2:
The system allows dynamic adjustment of autonomous decision-making capabilities. The owner can modify authorization parameters, spending limits, and transaction permissions at any time, and these changes are reflected in the token's constraints. This dynamic approach enables the appliance to have flexible autonomous capability that adapts to the owner's changing preferences and risk tolerance.
Data Source
AI summary
Provided herein is a computer-implemented method for provisioning a token to an appliance. The method includes registering an original account identifier to an appliance, wherein the original account identifier is not associated with any user when registered, associating a device token to the original account identifier, wherein the device token is stored by the appliance, associating a user account identifier to at least one of the device token and the original account identifier, receiving, from the appliance, a transaction request for a transaction, the transaction request including the device token, identifying the user account identifier based on the device token, determining that the transaction is authorized based at least partially on the user account identifier and the original account identifier registered to the at least one appliance, and in response to determining that the transaction is authorized, processing the transaction. A system and appliance are also disclosed.


