Mobile Access Data Provisioning via Validation Entity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for provisioning access data to mobile devices are insecure, particularly when multiple entities are involved, as they expose sensitive authentication data to man-in-the-middle attacks and lack adequate protection, leading to trust issues and security concerns.

Innovation Solution

A system where a validation entity computer receives an authentication code, decrypts it to obtain access data, and initiates provisioning to a mobile device, ensuring secure transmission and verification through a trusted application, using an encrypted time data element to validate the code's validity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple entities are involved in provisioning access data to mobile devices, then the system can support diverse resource providers and services, but sensitive authentication data is exposed to man-in-the-middle attacks and hacking

Engineering Contradiction:
Improveability to support multiple resource providersVSAvoidexposure to man-in-the-middle attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a validation entity computer as an intermediary between the mobile device and resource providers. This mediator receives authentication codes, validates them, and only then provisions access data to trusted applications. The intermediary architecture allows multiple resource providers to be supported while centralizing security validation to prevent man-in-the-middle attacks, as all authentication flows through this trusted intermediate layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If access data is transmitted through multiple entities in the provisioning process, then comprehensive service coverage is achieved, but confidential information of the user is inadequately protected

Engineering Contradiction:
Improveservice coverage across multiple entitiesVSAvoidprotection of confidential information
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary validation of authentication codes before access data is provisioned. The validation entity computer verifies the authentication code in advance, checks its integrity and expiration, and only then allows the provisioning process to proceed. This preliminary action ensures that even though multiple entities are involved in the service coverage, the confidential information is protected because validation occurs before any sensitive data transmission.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If a single application performs multiple functions for different resource providers, then device functionality is enhanced, but trust and security control are compromised

Engineering Contradiction:
Improvemulti-functionality of applicationVSAvoidtrust and security control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the authentication and validation processes from the application layer. Instead of relying on a single application to handle both resource provider interactions and security validation, the system separates these functions: the application handles user interface and resource provider communication, while a separate validation entity computer handles authentication code validation and security decisions. This segmentation allows the application to be versatile while maintaining centralized security control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10959093B2Method and system for provisioning access data to mobile device
Publication Date: 2021.03.23 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US10959093B2 patent drawing
  • US10959093B2 patent drawing
  • US10959093B2 patent drawing

AI summary

A method and system for provisioning access data in a second application on a mobile device using a first application on the mobile device. Authentication data may be input into the first application, and an authentication code may be requested from a remote server. The authentication code may include access data to be provisioned, in encrypted form. After the authentication code is received by the first application in the mobile device, it can pass the authentication code to a second application that initiates an access data provisioning process.