Credential Provisioning via Encrypted Nonce Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for provisioning credentials across multiple user devices are cumbersome and often impossible, especially when trying to share credentials between devices not under the user's control, such as those owned by friends or family members.

Innovation Solution

A system that allows a user to request and automatically provision credentials, like electronic passes or payment information, on multiple devices using a provisioning system that generates and encrypts a nonce and provisioning certificate, enabling secure and efficient transfer of credentials through a messaging system without requiring extensive user input or authentication on each target device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional methods are used for provisioning credentials across multiple user devices, then security can be maintained through traditional authentication protocols, but the process becomes cumbersome and impossible for devices not under user control

Engineering Contradiction:
Improvecredential provisioning capabilityVSAvoidprovisioning process complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

A provisioning server acts as an intermediary between the credential issuing system and multiple user devices. The server receives provisioning requests, generates encrypted provisioning packages containing credentials, and distributes them to authorized devices through a messaging system, eliminating the need for direct device-to-device credential transfer and complex manual authentication on each target device

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and credential packaging actions on the provisioning server before distribution. The server pre-generates encrypted provisioning packages with embedded credentials and authorization tokens in advance, so that when credentials need to be provisioned on new devices, the distribution process is already prepared and simplified

Inventive Principle:
Principle #10Preliminary action

2Reliability

If extensive authentication and data exchange are performed on each target device, then security is enhanced, but bandwidth and power consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The provisioning server consolidates authentication and security verification functions, performing centralized security checks before credential distribution. This eliminates the need for each target device to perform extensive independent authentication sequences, reducing computational overhead and power consumption on mobile devices while maintaining security through server-side verification

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates encrypted copies of credentials in provisioning packages that can be securely distributed to multiple devices. Each device receives a cryptographically secured copy of the necessary credential data, eliminating the need for repeated authentication handshakes and data exchange protocols on each device, thereby reducing bandwidth and power usage

Inventive Principle:
Principle #26Copying

3Reliability

If manual user input and authentication are required on each target device, then security control is maintained, but the number of provisioning steps increases

Engineering Contradiction:
Improveauthentication controlVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The provisioning server mediates the authentication process by verifying user identity and device authorization centrally, then automatically distributing credentials to approved devices. This eliminates the need for users to manually authenticate on each target device while maintaining security control through server-side verification, significantly reducing the number of interaction steps required

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service credential provisioning where authorized users can initiate credential distribution to their devices through a simple interface, and the provisioning server automatically handles the complex authentication, encryption, and credential deployment processes without requiring manual user input on each target device

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12088740B2Secure sharing of credential information
Publication Date: 2024.09.10 APPLE INC
  • US12088740B2 patent drawing
  • US12088740B2 patent drawing
  • US12088740B2 patent drawing

AI summary

A first user device may be used to request provisioning of a secure credential on a second user device. A provisioning system may facilitate the provisioning in a manner that ensures security and privacy of the requesting parties. The provisioning requests may be made using an application on the first user device such as a third-party application or using a web application via a browser. The credential may be added to a digital wallet on the second user device. The credential may be useable by the second user device to perform one or more contactless transactions.