Mobile Credential Management for Offline Transit Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In HCE-based transaction applications for mass transit systems, users may lose connectivity after entry, leading to depleted limited-use credentials (LUCs), preventing them from exiting the system or resulting in overcharging, as there is no way to replenish LUCs during a journey if the device loses connectivity or power.
Innovation Solution
A method and system where a mobile device receives and stores application sequence counter values, LUCs, emergency credentials, and an account token, allowing it to transmit an application cryptogram from emergency credentials when LUCs are depleted, and updates the sequence counter, enabling subsequent online replenishment of credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If LUCs are stored on the mobile device for offline transaction authentication, then the device can operate without connectivity, but the credentials may be depleted and cannot be replenished if connectivity is lost
Solution Approach 1:
The system pre-provisions a pool of Limited Use Credentials (LUCs) to the mobile device before offline operation begins. This allows the device to perform multiple transactions without connectivity. The server system anticipates the need for offline operation and loads sufficient credentials in advance, resolving the contradiction by ensuring both operational reliability and the ability to handle credential depletion scenarios.
Solution Approach 2:
The patent introduces an intermediary mechanism where the mobile device maintains a local credential pool that acts as a buffer between the server system and the transaction authentication process. This intermediary credential pool allows transactions to proceed offline while preventing direct dependency on continuous server connectivity, thus resolving the contradiction between offline reliability and replenishment capability.
2Reliability
If the master key is stored in volatile memory for secure LUC access, then security is improved, but the credentials become inaccessible when the device is powered off
Solution Approach 1:
The system provisions multiple LUCs in advance to the mobile device, creating a cushion or buffer of credentials that can be used offline. This pre-loaded credential pool compensates for the security measure of storing the master key in volatile memory only, ensuring that even when the device is powered off and credentials are inaccessible, there are sufficient pre-provisioned credentials to complete the journey without requiring real-time server access.
3Reliability
If LUCs are limited to predetermined transactions or time periods, then security is enhanced, but users cannot complete journeys if credentials are depleted during travel
Solution Approach 1:
The server system performs preliminary action by provisioning a sufficient pool of LUCs to the mobile device before the user begins their journey or before offline operation is anticipated. This ensures that the limited-use credentials have enough capacity to cover the entire journey duration and transaction count, preventing credential depletion mid-journey while maintaining the security benefits of limited-use constraints.
Solution Approach 2:
The system uses partial action by provisioning credentials with a usage limit that exceeds the expected minimum requirements for a journey. This excessive provisioning ensures that even if usage patterns vary or unexpected transactions occur, the user will not deplete credentials during travel. The server can then validate and adjust the actual usage after connectivity is restored.
Data Source
AI summary
The present disclosure relates to credential management for mobile devices that can be used for access to secured physical environments. One aspect comprises a computer implemented method comprising a server system: receiving, from a mobile computing device, a provisioning request, which includes an account credential; authenticating the provisioning request based on the mobile computing device being linked to an account indicated by the account credential; generating an account token, which is bound to the account credential; generating one or more limited-use credentials (LUCs), using an application sequence counter, each of the one or more LUCs associated with a corresponding application sequence counter value; generating one or more emergency credentials; and transmitting, to the mobile computing device, the account token, the one or more LUCs, the application sequence counter values, and the one or more emergency credentials.


