Inter-device Credential Transfer for Mobile Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile payment systems, stored value credentials cannot be seamlessly transferred between devices, such as from a mobile phone to a smartwatch, due to the requirement that monetary value exists only on one device at a time, differing from credit card systems where value is centrally managed.

Innovation Solution

An inter-device credential transfer system that coordinates the removal of a stored value payment applet from one device and provisions it on another, ensuring the monetary value is only accessible on one device at a time, using a network environment with mobile and service provider servers to manage the transfer process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If stored value credentials are transferred between devices, then user convenience and accessibility are improved, but system complexity and security management become worsened

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a credential transfer service as an intermediary system that manages the transfer of stored value credentials between devices. This service acts as a mediator that coordinates the freezing of credentials on source devices, validates transfer requests, and provisions credentials on target devices, thereby simplifying the overall process while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The credential transfer process is divided into distinct operational stages: credential freezing on the source device, transfer validation by the service, and credential provisioning on the target device. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while enabling seamless transfers.

Inventive Principle:
Principle #1Segmentation

2Reliability

If stored value credentials are frozen on one device during transfer, then monetary value security is improved, but transfer time and process duration are worsened

Engineering Contradiction:
Improvemonetary value securityVSAvoidtransfer time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary freezing of the credential on the source device before completing the transfer process. This preliminary action ensures that the monetary value is secured and cannot be accessed or modified during the transfer, while the actual credential provisioning on the target device follows immediately, minimizing the perceived transfer time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The credential transfer process maintains continuous useful action by immediately provisioning the credential on the target device after freezing it on the source device. The system ensures uninterrupted service by quickly completing the transfer once security is established, reducing the effective time the credential is in a transitional state.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11321708B2Inter-device credential transfer
Publication Date: 2022.05.03 APPLE INC
  • US11321708B2 patent drawing
  • US11321708B2 patent drawing
  • US11321708B2 patent drawing

AI summary

A device implementing an inter-device credential transfer system may include at least one processor that is configured to receive a request to transfer a transaction credential from a first device to a second device, the transaction credential being associated with a stored monetary value and the request comprising a transaction credential identifier of the transaction credential. The at least one processor is further configured to prevent, responsive to the request, the transaction credential from being utilized for payment transactions by the first device. The at least one processor is further configured to provision an instance of the transaction credential on the second device. The at least one processor is further configured to cause the instance of the transaction credential to be activated on the second device with a balance corresponding to the stored monetary value associated with the transaction credential.