M2M Credential Provisioning for Secure Automated Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Households face inconvenience due to regular paper bills for goods and services, and existing technologies lack efficient methods for machine-to-machine interactions to manage resource usage and transactions without human intervention.

Innovation Solution

A system and platform that provisions consumer information onto machine-to-machine devices, enabling them to perform transactions using access credentials and policies, allowing machines to interact and manage resource usage independently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If machine-to-machine devices perform automated transactions without human intervention, then productivity and convenience are improved, but security risks and complexity of credential management increase

Engineering Contradiction:
Improveautomated transaction processingVSAvoidcredential management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

A provisioning server acts as an intermediary between users and machine-to-machine devices. The server receives user credentials, binds them to device identifiers, and provisions access credentials to devices automatically. This mediator handles the complex credential management logic centrally, reducing the complexity burden on individual devices while enabling automated transactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the potential harm of automated transactions (security risks from lack of human oversight) into a benefit by implementing automated security provisioning. The system automatically binds user identities to device credentials through cryptographic binding of device identifiers to user account information, ensuring security without requiring human intervention during transactions.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Extent of automation

If access credentials are stored on machine-to-machine devices, then automated resource acquisition is enabled, but security risks from credential exposure increase

Engineering Contradiction:
Improveautomated resource acquisitionVSAvoidcredential security
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The credential system is segmented into multiple components: device identifiers stored on devices, user account information stored securely on servers, and bound credentials provisioned to devices only when needed. This segmentation prevents complete credential exposure on any single device while enabling automated resource acquisition through the distributed credential architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary credential binding and provisioning before automated transactions occur. User credentials are bound to device identifiers in advance through the provisioning server, and access credentials are provisioned to devices before they need to acquire resources automatically. This preliminary setup ensures security is established before automation begins.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230145489A1Provisioning platform for machine-to-machine devices
Publication Date: 2023.05.11 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20230145489A1 patent drawing
  • US20230145489A1 patent drawing
  • US20230145489A1 patent drawing

AI summary

Techniques described herein include a platform and process for provisioning user information onto a machine-to-machine device in order to enable the machine-to-machine device to conduct transactions utilizing the user information. In some embodiments, a user device is used to relay information between a machine-to-machine device and a provisioning service provider computer. In some embodiments, a machine-to-machine device is connected to the provisioning service provider computer via a network connection. Upon receiving a request to provision the machine-to-machine device, the service provider computer may identify the device from a device identifier. The service provider computer may generate an access credential or token for the machine-to-machine device. The access credential, token, and/or one or more policies may be provisioned onto the machine-to-machine device.