Limited-Use Key Exchange via Access Device Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Portable communication devices without long-range communication capabilities or access to remote provisioning servers face challenges in receiving encryption keys, leading to secure and reliable transaction issues, especially in devices like payment cards and wearable devices.
Innovation Solution
Implementing limited-use encryption keys that can be replenished via short-range wireless communication or contact connections with access devices like POS terminals, allowing transactions without relying on long-range communication with remote servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If portable communication devices use pre-loaded encryption keys at manufacture, then the devices can conduct access transactions without long-range communication capabilities, but the keys cannot be replenished when expired or lost, prohibiting further transactions
Solution Approach 1:
The patent introduces an access device (such as a POS terminal) as an intermediary between the portable communication device and the remote provisioning server. The access device receives requests from the portable device, communicates with the server to obtain new encryption keys, and delivers them back to the portable device. This mediator enables key replenishment for devices that lack direct long-range communication capabilities.
Solution Approach 2:
The system segments the key replenishment function into separate components: the portable communication device retains only short-range communication capabilities for transaction operations, while the access device handles the complex key management and server communication. This segmentation allows the portable device to remain simple and secure while still enabling key replenishment through the access device.
2Ease of operation
If portable communication devices rely on long-range cellular networks to receive encryption keys, then keys can be provisioned remotely, but the devices cannot obtain keys in areas without cellular coverage or when networks are down
Solution Approach 1:
The system performs preliminary actions by pre-loading encryption keys into the portable communication device at manufacture or initial setup. These pre-loaded keys enable the device to conduct transactions immediately without requiring cellular network connectivity, ensuring transaction availability in areas without coverage or when networks are down.
Solution Approach 2:
The access device serves as a local intermediary that can replenish encryption keys without requiring continuous cellular network connectivity. The portable device can present its identifier to the access device via short-range communication, and the access device will obtain new keys from the remote server and deliver them locally, bypassing the need for the portable device to have direct cellular access.
3Reliability
If portable communication devices without secure elements use limited-use encryption keys, then security is enhanced with limited lifespan keys, but the devices need regular key replenishment which requires additional communication infrastructure
Solution Approach 1:
The patent extracts the complex key management and server communication functions from the portable communication device and places them in the access device. The portable device only needs to store its identifier and execute simple local operations, while the access device handles the complex tasks of communicating with the remote provisioning server and managing the encryption key lifecycle. This extraction reduces the complexity burden on the portable device.
Solution Approach 2:
The system implements self-service by enabling the portable communication device to autonomously initiate key replenishment requests using its stored identifier and short-range communication capabilities. The device can present its identifier to the access device, which then automatically retrieves new encryption keys from the remote server and delivers them, without requiring user intervention or complex device logic.
Data Source
AI summary
Encryption key exchange processes are disclosed. A disclosed method includes initiating communication between a portable communication device including a token and a first limited use encryption key, and an access device. After communication is initiated, the portable communication device receives a second limited use key from a remote server via the access device. The portable communication device then replaces the first limited use key with the second limited use key. The second limited use key is thereafter used to create access data such as cryptograms that can be used to conduct access transactions.


