Credential Provisioning Across Multiple Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face complications in securely transferring and sharing payment credentials between multiple electronic devices, as existing security requirements often prevent seamless data transfer, especially when switching or upgrading devices, leading to a cumbersome re-provisioning process.

Innovation Solution

A method where a first electronic device provisions credentials with independent and unique portions, storing them on an external medium, allowing a second device to retrieve and re-provision these credentials using its own secure element and unique information, thereby streamlining the transfer and reuse of credentials without repeating the full provisioning process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security requirements are strengthened to protect payment information in electronic transactions, then security of electronic transactions is improved, but user interaction becomes more complex and user experience is frustrated

Engineering Contradiction:
Improvesecurity of electronic transactionsVSAvoiduser interaction complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The credential data is segmented into multiple portions: a first portion that is device-independent and can be stored externally, and a second portion that is device-specific and stored in a secure element. This segmentation allows the device-independent portion to be transferred between devices without requiring complex re-provisioning, thereby reducing user interaction complexity while maintaining security through the device-specific portion.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An external storage medium acts as an intermediary between the first electronic device and the second electronic device, storing the device-independent portion of the credential. This intermediary enables seamless transfer of credentials between devices without requiring users to manually re-enter information, thus improving ease of operation while maintaining security through the secure element on each device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security requirements are strengthened to protect payment information, then security of electronic transactions is improved, but credential transfer between multiple devices is prevented

Engineering Contradiction:
Improvesecurity of electronic transactionsVSAvoidcredential sharing between devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

By dividing the credential into device-independent and device-specific portions, the system enables credential sharing across multiple devices (improving adaptability) while the device-specific portion stored in the secure element maintains security requirements (preserving reliability).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The credential provisioning is extended from a single-device model to a multi-device model by introducing the dimension of credential portions. The device-independent portion can be shared across devices while the device-specific portion maintains security, allowing credential transfer without compromising security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If full provisioning process is repeated on each new device, then security is maintained, but user time and effort are wasted

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidre-provisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The device-independent portion of the credential is prepared in advance and stored on an external storage medium. When a user switches to a new device, this pre-prepared portion can be quickly transferred and combined with the device-specific portion, eliminating the need to repeat the full provisioning process and reducing re-provisioning time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If credentials are stored only in device-specific secure elements, then security is ensured, but credential transfer between devices becomes impossible

Engineering Contradiction:
Improvecredential securityVSAvoiddevice portability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The credential is segmented into a device-independent portion stored externally and a device-specific portion stored in the secure element. This segmentation enables credential transfer between devices through the external portion while the secure element portion ensures security, thus achieving both device portability and credential security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230122885A1Provisioning credentials on multiple electronic devices
Publication Date: 2023.04.20 APPLE INC
  • US20230122885A1 patent drawing
  • US20230122885A1 patent drawing
  • US20230122885A1 patent drawing

AI summary

This application relates to re-provisioning of credentials, such as payment credentials, on a second electronic device from one or more credentials previously provisioned on a first electronic device. The one or more previously provisioned credentials may be stored on an external storage system and may be retrieved by the second electronic device for re-provisioning. The second electronic device may re-provision an instance of the one or more retrieved credentials for use in electronic transactions on the second electronic device using a secure element linked to the second electronic device and information that is unique to the one or more credentials being re-provisioned to the second electronic device.