Provisioning Credentials to Secondary Devices via Intermediary Subsystem
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in efficiently provisioning and managing multiple commerce credentials across multiple electronic devices, particularly when trying to perform NFC-based financial transactions, as existing methods require manual entry of credentials on each device, which is tedious and insecure.
Innovation Solution
A system and method that allows provisioning of payment cards onto a secondary user device via a primary user device, using a service provider subsystem, payment network subsystem, and secure elements with unique identifiers, enabling secure and efficient transfer of digital wallet passes and personalization scripts to enable NFC transactions without direct input on the secondary device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If manual entry of credentials is performed on each device, then credentials can be provisioned onto multiple devices, but the process becomes tedious and insecure
Solution Approach 1:
A service provider subsystem acts as an intermediary between the primary device and secondary device. The subsystem receives device information from the primary device, sends digital wallet passes to the secondary device through the primary device, and manages secure element personalization scripts. This intermediary approach eliminates the need for manual credential entry on each device while maintaining security through centralized control.
Solution Approach 2:
The system creates a copy of the credential provisioning process through digital wallet passes. Instead of manually entering credentials on each device, the credential data is copied and transferred digitally from the primary device to the secondary device via the service provider subsystem, significantly reducing user effort while maintaining credential integrity.
2Adaptability or versatility
If manual entry of credentials is performed on each device, then credentials can be provisioned onto multiple devices, but security is compromised
Solution Approach 1:
The service provider subsystem serves as a secure intermediary that manages credential distribution. It receives device information from the primary device, authenticates the secondary device through the broker module, and sends digital wallet passes through verified channels. This intermediary layer ensures that credentials are provisioned securely without requiring manual entry on each device, maintaining both multi-device capability and security.
Solution Approach 2:
The system performs preliminary authentication and device verification before credential provisioning. The broker module pairs the secure element identifier with the push token in advance, and the service provider subsystem validates device information before sending digital wallet passes. This preliminary action ensures that only authorized devices receive credentials, maintaining security while enabling multi-device provisioning.
3Productivity
If service provider subsystem manages credential provisioning through primary device, then provisioning becomes secure and efficient, but system complexity increases
Solution Approach 1:
The system is segmented into distinct functional modules: the service provider subsystem for managing credential provisioning, the broker module for pairing secure element identifiers with push tokens, the trusted service manager for personalization scripts, and the primary/secondary devices for credential storage and transmission. This segmentation allows each component to perform its specific function efficiently while maintaining overall system productivity, despite the increased architectural complexity.
Data Source
AI summary
A system for provisioning credentials onto an electronic device is provided. The system may include a payment network subsystem, a service provider subsystem, a primary user device, and a secondary user device. The user may select a particular payment card to provision onto the secondary user device by providing an input at the primary user device. A broker module running on the service provider subsystem may then transfer a disabled pass to the secondary user device. Concurrently, the payment network subsystem may direct a trusted service manager module on the service provider subsystem to write credential information onto a secure element within the secondary user device. Once the secure element has been updated, the broker module may provide an activated pass to the secondary user device so that the secondary user device can be used to perform NFC-based financial transactions at a merchant terminal.


