Credential Provisioning via Device Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing credential provisioning processes face challenges in ensuring that the correct user and device are authorized, and there is a need for more convenient, efficient, and secure methods to coordinate between different entities involved in provisioning access credentials on mobile devices.

Innovation Solution

The method involves providing a device code to an authorization computer, which generates an authorization code, and this code is used to verify the user and device, ensuring secure provisioning of access credentials through a server computer, allowing the mobile device to access resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional credential provisioning methods are used, then credentials can be provisioned to mobile devices, but the coordination between different entities (credential issuing entity and authorizing entity) becomes complex and difficult to manage

Engineering Contradiction:
Improveease of credential provisioningVSAvoidsystem coordination complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary credential provisioning system that acts as a mediator between the credential issuing entity and the authorizing entity. This intermediary receives provisioning requests, generates credentials, and coordinates with both entities through standardized interfaces, thereby simplifying the overall system complexity while maintaining secure credential provisioning capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional authentication processes are used, then credentials can be issued, but it becomes difficult to ensure that the requesting entity is authorized and the target device is correct

Engineering Contradiction:
Improveauthorization verification reliabilityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the authorizing entity provides authorization decisions back to the intermediary provisioning system. The system verifies device identities through structured verification processes and provides confirmation feedback to ensure that only authorized entities receive credentials for the correct target devices, thereby enhancing reliability through systematic verification and feedback loops

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple entities are involved in credential provisioning, then security can be enhanced through multiple authorization layers, but the provisioning process becomes less efficient and more time-consuming

Engineering Contradiction:
Improvesecurity assuranceVSAvoidprovisioning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having the intermediary provisioning system pre-generate credentials and pre-establish verification protocols before actual credential issuance. The system prepares authorization codes and verification mechanisms in advance, allowing multiple security checks to be performed more efficiently without significantly delaying the provisioning process, thus maintaining security while improving productivity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11880829B2Provisioning of access credentials using device codes
Publication Date: 2024.01.23 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11880829B2 patent drawing
  • US11880829B2 patent drawing
  • US11880829B2 patent drawing

AI summary

Systems and methods are described for provisioning access credentials to a mobile device using device and authorization codes. Once provisioned, a mobile device can be used to conduct a transaction.