Credential Provisioning via Encrypted Token Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for provisioning credentials across multiple user devices are cumbersome and often impossible, especially when dealing with devices not under the user's control, requiring repetitive authentication processes and manual input.

Innovation Solution

A computer-implemented method that enables a first user device to request and provision credentials on a second user device using a nonce and provisioning certificate, encrypting a provisioning target package that is securely transmitted and decrypted on the target device, allowing for automated provisioning without the need for extensive user interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional methods are used for provisioning credentials across multiple user devices, then manual input and repetitive authentication processes are required, but this increases device complexity and user interaction requirements

Engineering Contradiction:
Improvecredential provisioning processVSAvoidauthentication process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-establishing trust relationships between devices through device pairing and generating provisioning tokens in advance. The first user device is paired with the provisioning system beforehand, allowing it to generate tokens that automatically establish trust with target devices without requiring manual authentication during credential provisioning.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a provisioning system as an intermediary between user devices. This intermediary manages credential provisioning by receiving requests from the first user device, validating provisioning tokens, and securely distributing credentials to target devices. The messaging system also acts as an intermediary for secure communication and token transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 3:

The system enables self-service by allowing the first user device to autonomously generate provisioning tokens and initiate credential provisioning to target devices without requiring manual authentication from the target device user. The automated token validation and credential distribution process eliminates the need for repetitive manual authentication steps.

Inventive Principle:
Principle #25Self-service

2Reliability

If extensive user interaction is required for credential provisioning, then security may be improved through verification, but this increases loss of time and reduces productivity

Engineering Contradiction:
Improvecredential securityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security verification is performed in advance through device pairing and token generation. The first user device pairs with the provisioning system beforehand, establishing a trusted relationship. Provisioning tokens are generated with embedded security validations, so that when credentials are provisioned to target devices, the security verification has already occurred, eliminating the need for time-consuming authentication during the actual provisioning process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated provisioning system performs security validations autonomously through token validation and device verification processes. The messaging system automatically verifies provisioning tokens and the provisioning system validates credentials without requiring manual user verification, maintaining security while significantly reducing the time required for credential provisioning.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If credential information is transmitted between devices, then provisioning capability is improved, but this increases bandwidth consumption and power usage

Engineering Contradiction:
Improvecredential sharing capabilityVSAvoiddata transmission energy
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system extracts and transmits only the essential credential information and provisioning tokens rather than complete credential datasets. The provisioning token contains minimal necessary information for credential distribution, and the messaging system transmits only authenticated data packets, reducing the volume of data transmitted between devices and lowering bandwidth consumption and power usage.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If manual authentication processes are used for each device, then security verification is thorough, but this increases device complexity and reduces ease of operation

Engineering Contradiction:
Improveauthentication verificationVSAvoidcredential provisioning
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Authentication verification is performed in advance through device pairing with the provisioning system and token generation. The first user device establishes a trusted relationship with the provisioning system beforehand, and provisioning tokens are generated with embedded security validations. This preliminary authentication ensures thorough verification while eliminating the need for repeated manual authentication during credential provisioning to multiple devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The provisioning system performs automated authentication verification through token validation and device identity verification without requiring manual user authentication for each device. The system autonomously verifies the legitimacy of provisioning requests and validates credentials, maintaining thorough security verification while significantly improving ease of operation by eliminating repetitive manual authentication steps.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11606217B2Secure sharing of credential information
Publication Date: 2023.03.14 APPLE INC
  • US11606217B2 patent drawing
  • US11606217B2 patent drawing
  • US11606217B2 patent drawing

AI summary

A first user device may be used to request provisioning of a secure credential on a second user device. A provisioning system may facilitate the provisioning in a manner that ensures security and privacy of the requesting parties. The provisioning requests may be made using an application on the first user device such as a third-party application or using a web application via a browser. The credential may be added to a digital wallet on the second user device. The credential may be useable by the second user device to perform one or more contactless transactions.