Secure Credential Provisioning Platform with Multi-Source Fraud Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for securely provisioning commerce credentials on electronic devices for near field communications lack comprehensive fraud risk analysis, leading to potential security vulnerabilities and user inconvenience in financial transactions.

Innovation Solution

A secure platform system that authenticates user accounts, performs commercial entity and financial entity fraud checks, and facilitates credential provisioning on electronic devices, leveraging a processor, memory, and communications components to ensure secure and seamless transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive fraud risk analysis is performed through multiple data sources, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The fraud risk analysis system is segmented into multiple independent data sources (commercial entity data source, financial institution data source, additional data source) that can be selectively activated. Each data source operates as a separate module that contributes specific types of fraud risk information, allowing the system to achieve comprehensive security analysis while maintaining modularity and manageable complexity through clear separation of functions.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If multiple data sources are used for fraud risk analysis, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improvefraud risk analysis precisionVSAvoiddata source integration complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

A credential provisioning system acts as an intermediary layer between multiple data sources and the credential provisioning process. This intermediary receives fraud risk data from commercial entities, financial institutions, and additional data sources, integrates the information through standardized processing, and makes provisioning decisions. The intermediary simplifies the complexity of integrating multiple data sources by providing a unified interface and centralized coordination mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If automated credential provisioning is implemented, then ease of operation is improved, but security risks increase

Engineering Contradiction:
Improvecredential provisioning easeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary fraud risk analysis using multiple data sources before credential provisioning is executed. By conducting comprehensive security checks, commercial entity verification, and financial institution validation in advance of the actual provisioning action, the system ensures that automated provisioning maintains high security standards while providing ease of operation. The preliminary actions filter out high-risk cases before they reach the automated provisioning stage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4152187B1Secure provisioning of credentials on an electronic device
Publication Date: 2024.11.13 APPLE INC
  • EP4152187B1 patent drawingFigure 1
  • EP4152187B1 patent drawingFigure 2
  • EP4152187B1 patent drawingFigure 3

AI summary

Systems, methods, and computer-readable media for provisioning credentials on an electronic device are provided. In one example embodiment, a secure platform system may be in communication with an electronic device and a financial institution subsystem. The secure platform system may be configured to, inter alia, receive user account information from the electronic device, authenticate a user account with a commercial entity using the received user account information, detect a commerce credential associated with the authenticated user account, run a commercial entity fraud check on the detected commerce credential, commission the financial institution subsystem to run a financial entity fraud check on the detected commerce credential based on the results of the commercial entity fraud check, and facilitate provisioning of the detected commerce credential on the electronic device based on the results of the financial entity fraud check. Additional embodiments are also provided.