Provisioning Credentials to Secondary Devices via Intermediary Subsystem

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in efficiently provisioning and managing multiple commerce credentials across multiple electronic devices, particularly when trying to perform NFC-based financial transactions, as existing methods require manual entry of credentials on each device, which is tedious and insecure.

Innovation Solution

A system and method that allows provisioning of payment cards onto a secondary user device via a primary user device, using a service provider subsystem, payment network subsystem, and secure elements with unique identifiers, enabling secure and efficient transfer of digital wallet passes and personalization scripts to enable NFC transactions without direct input on the secondary device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual entry of credentials is performed on each device, then credentials can be provisioned onto multiple devices, but the process becomes tedious and insecure

Engineering Contradiction:
Improvecredential provisioning capabilityVSAvoidprovisioning process simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

A service provider subsystem acts as an intermediary between the primary device and secondary device. The subsystem receives device information from the primary device, sends digital wallet passes to the secondary device through the primary device, and manages secure element personalization scripts. This intermediary approach eliminates the need for manual credential entry on each device while maintaining security through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the credential provisioning process through digital wallet passes. Instead of manually entering credentials on each device, the credential data is copied and transferred digitally from the primary device to the secondary device via the service provider subsystem, significantly reducing user effort while maintaining credential integrity.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If manual entry of credentials is performed on each device, then credentials can be provisioned onto multiple devices, but security is compromised

Engineering Contradiction:
Improvemulti-device credential provisioningVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The service provider subsystem serves as a secure intermediary that manages credential distribution. It receives device information from the primary device, authenticates the secondary device through the broker module, and sends digital wallet passes through verified channels. This intermediary layer ensures that credentials are provisioned securely without requiring manual entry on each device, maintaining both multi-device capability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and device verification before credential provisioning. The broker module pairs the secure element identifier with the push token in advance, and the service provider subsystem validates device information before sending digital wallet passes. This preliminary action ensures that only authorized devices receive credentials, maintaining security while enabling multi-device provisioning.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If service provider subsystem manages credential provisioning through primary device, then provisioning becomes secure and efficient, but system complexity increases

Engineering Contradiction:
Improveprovisioning efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system is segmented into distinct functional modules: the service provider subsystem for managing credential provisioning, the broker module for pairing secure element identifiers with push tokens, the trusted service manager for personalization scripts, and the primary/secondary devices for credential storage and transmission. This segmentation allows each component to perform its specific function efficiently while maintaining overall system productivity, despite the increased architectural complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11922408B2Apparatuses and methods for using a primary user device to provision credentials onto a secondary user device
Publication Date: 2024.03.05 APPLE INC
  • US11922408B2 patent drawing
  • US11922408B2 patent drawing
  • US11922408B2 patent drawing

AI summary

A system for provisioning credentials onto an electronic device is provided. The system may include a payment network subsystem, a service provider subsystem, a primary user device, and a secondary user device. The user may select a particular payment card to provision onto the secondary user device by providing an input at the primary user device. A broker module running on the service provider subsystem may then transfer a disabled pass to the secondary user device. Concurrently, the payment network subsystem may direct a trusted service manager module on the service provider subsystem to write credential information onto a secure element within the secondary user device. Once the secure element has been updated, the broker module may provide an activated pass to the secondary user device so that the secondary user device can be used to perform NFC-based financial transactions at a merchant terminal.