Limited-Use Key Exchange via Access Device Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable communication devices without long-range communication capabilities or access to remote provisioning servers face challenges in receiving encryption keys, leading to secure and reliable transaction issues, especially in devices like payment cards and wearable devices.

Innovation Solution

Implementing limited-use encryption keys that can be replenished via short-range wireless communication or contact connections with access devices like POS terminals, allowing transactions without relying on long-range communication with remote servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If portable communication devices use pre-loaded encryption keys at manufacture, then the devices can conduct access transactions without long-range communication capabilities, but the keys cannot be replenished when expired or lost, prohibiting further transactions

Engineering Contradiction:
Improvetransaction capabilityVSAvoidkey replenishment capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an access device (such as a POS terminal) as an intermediary between the portable communication device and the remote provisioning server. The access device receives requests from the portable device, communicates with the server to obtain new encryption keys, and delivers them back to the portable device. This mediator enables key replenishment for devices that lack direct long-range communication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the key replenishment function into separate components: the portable communication device retains only short-range communication capabilities for transaction operations, while the access device handles the complex key management and server communication. This segmentation allows the portable device to remain simple and secure while still enabling key replenishment through the access device.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If portable communication devices rely on long-range cellular networks to receive encryption keys, then keys can be provisioned remotely, but the devices cannot obtain keys in areas without cellular coverage or when networks are down

Engineering Contradiction:
Improveremote key provisioningVSAvoidtransaction availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-loading encryption keys into the portable communication device at manufacture or initial setup. These pre-loaded keys enable the device to conduct transactions immediately without requiring cellular network connectivity, ensuring transaction availability in areas without coverage or when networks are down.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access device serves as a local intermediary that can replenish encryption keys without requiring continuous cellular network connectivity. The portable device can present its identifier to the access device via short-range communication, and the access device will obtain new keys from the remote server and deliver them locally, bypassing the need for the portable device to have direct cellular access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If portable communication devices without secure elements use limited-use encryption keys, then security is enhanced with limited lifespan keys, but the devices need regular key replenishment which requires additional communication infrastructure

Engineering Contradiction:
ImprovesecurityVSAvoidkey management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex key management and server communication functions from the portable communication device and places them in the access device. The portable device only needs to store its identifier and execute simple local operations, while the access device handles the complex tasks of communicating with the remote provisioning server and managing the encryption key lifecycle. This extraction reduces the complexity burden on the portable device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements self-service by enabling the portable communication device to autonomously initiate key replenishment requests using its stored identifier and short-range communication capabilities. The device can present its identifier to the access device, which then automatically retrieves new encryption keys from the remote server and delivers them, without requiring user intervention or complex device logic.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11714885B2Encryption key exchange process using access device
Publication Date: 2023.08.01 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11714885B2 patent drawing
  • US11714885B2 patent drawing
  • US11714885B2 patent drawing

AI summary

Encryption key exchange processes are disclosed. A disclosed method includes initiating communication between a portable communication device including a token and a first limited use encryption key, and an access device. After communication is initiated, the portable communication device receives a second limited use key from a remote server via the access device. The portable communication device then replaces the first limited use key with the second limited use key. The second limited use key is thereafter used to create access data such as cryptograms that can be used to conduct access transactions.