Credential Delivery Device for Multi-Format Wallet Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of provisioning credentials for different electronic wallet providers in electronic locks is exacerbated by the uncertainty of which wallet application is installed on a user's device, making it difficult to support multiple formats and ensuring secure access to restricted physical spaces.
Innovation Solution
A credential delivery device generates a credential identifier and packages the credential in formats compatible with various electronic wallet providers, enabling secure delivery to user devices for unlocking electronic locks, even when the provider is unknown at the time of credential generation, and includes verification mechanisms to prevent reuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If credentials are packaged in multiple formats for different electronic wallet providers, then compatibility with various wallet applications is improved, but device complexity increases
Solution Approach 1:
The credential packaging process is segmented into distinct format-specific packages for different electronic wallet providers (e.g., Google Wallet, Apple Wallet, Samsung Wallet). Each provider receives a credential packaged in their specific format, allowing the system to support multiple wallet applications without requiring a single complex monolithic packaging solution.
Solution Approach 2:
The credential delivery device acts as an intermediary between the electronic access control system and multiple electronic wallet providers. It receives credentials from the access control system, packages them in appropriate formats for different wallet providers, and distributes them accordingly, thereby simplifying the overall provisioning process while maintaining broad compatibility.
2Adaptability or versatility
If credential packaging is performed after receiving provider-specific requests, then adaptability to different wallet providers is improved, but loss of time occurs due to waiting for requests
Solution Approach 1:
The system performs preliminary actions by maintaining a pool of pre-packaged credentials in various formats ready for distribution. When a user requests a credential, the system can quickly match and deliver an appropriate pre-packaged credential without needing to perform format conversion at the moment of request, thereby reducing delivery time while maintaining adaptability.
Solution Approach 2:
The credential delivery system dynamically adapts its response based on the specific electronic wallet provider identified in the incoming request. By using the credential identifier to determine the appropriate format and selecting from pre-packaged options or generating the appropriate format on-demand, the system optimizes delivery speed while maintaining support for multiple wallet providers.
3Reliability
If credential identifiers are verified against used identifiers, then security against credential reuse is improved, but device complexity increases
Solution Approach 1:
The credential delivery device implements a feedback mechanism by maintaining and consulting a record of used credential identifiers. Before issuing a credential, the system verifies that the identifier has not been previously used, providing feedback control that prevents credential reuse attacks while maintaining a relatively simple verification process.
Solution Approach 2:
Instead of implementing complex cryptographic verification mechanisms, the system uses a simplified approach by maintaining copies of used credential identifiers in a database or data structure. This allows for efficient comparison and verification without requiring sophisticated security algorithms, thereby achieving good security with minimal added complexity.
Data Source
AI summary
It is provided a method for providing a credential for use with an electronic lock (7) to access to restricted physical space (16). The method comprises: receiving (40) a credential that unlocks the electronic lock (7); generating (42) a credential identifier associated with the credential; sending (44) the credential identifier to an EAC (5); receiving (46), from an electronic wallet provider (6), a request for the credential, wherein the request comprises the credential identifier; packaging (48) the credential, resulting in packaged credential, wherein the packaging complies with a format, selected from a plurality of formats for different electronic wallet providers, corresponding to the electronic wallet provider from which the request is received, enabling the credential to be provided to an electronic wallet in a user device (2) for unlocking the electronic lock (7); and sending (50) the packaged credential to the electronic wallet provider (6).


