Risk-Based Mobile Credential Provisioning with Non-Override Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile device credential provisioning lacks effective and secure processes to ensure that payment accounts are provisioned to rightful owners, as existing methods fail to adequately address risks of unauthorized provisioning and do not interrupt or delay the provisioning process.
Innovation Solution
A risk-based provisioning scheme that selectively chooses from multiple paths based on perceived risk levels, involving immediate provisioning for low risk, denial for high risk, and additional user authentication for medium risk, with the option to provision credentials in an inactive state and activate later, using a non-override condition to set risk levels and require additional authentication when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional authentication processes are implemented to verify rightful ownership, then security is improved, but provisioning time and process complexity increase
Solution Approach 1:
The patent implements dynamic risk-based authentication that adjusts the provisioning process based on assessed risk levels. Low-risk transactions proceed quickly with minimal authentication, while high-risk transactions trigger additional verification steps. This dynamic adaptation resolves the contradiction by making security measures proportional to actual risk rather than applying uniform authentication to all cases.
Solution Approach 2:
The system changes authentication parameters (such as requiring additional verification methods or increasing verification stringency) based on risk level assessments. By parameterizing the authentication process rather than using a fixed approach, the system can intensify security measures only when necessary, thus maintaining speed for low-risk cases while ensuring security for high-risk cases.
2Reliability
If multiple authentication channels are used to verify user identity, then authentication reliability is improved, but device complexity increases
Solution Approach 1:
The patent segments the authentication process into distinct channels (SMS, email, voice call, in-app) that can be independently selected based on risk level. Rather than implementing all authentication mechanisms simultaneously in the system, the solution divides authentication into modular components that are activated only when needed, reducing overall system complexity while maintaining high authentication reliability when required.
Solution Approach 2:
The system uses communication channels as intermediaries to verify user identity without requiring complex direct authentication infrastructure. By leveraging existing communication channels (SMS providers, email servers, voice call systems) as intermediaries, the patent achieves high authentication reliability while avoiding the need to build and maintain complex proprietary authentication infrastructure.
3Reliability
If credentials are provisioned in inactive state requiring later activation, then security is improved, but user convenience deteriorates
Solution Approach 1:
The patent performs preliminary credential provisioning in an inactive state for high-risk cases, preparing the credentials in advance but keeping them dormant until activation. This preliminary action allows the system to pre-verify and prepare credentials securely, then activate them only after additional authentication confirms rightful ownership. The benefit is that the heavy security verification is done beforehand, and activation itself is a simple user action.
Solution Approach 2:
For low-risk cases, the patent skips the intermediate inactive state entirely and provisions credentials directly to active status, rushing through the provisioning process without delay. This selective skipping ensures that users experiencing low-risk transactions enjoy immediate convenience, while only high-risk cases undergo the additional activation step, minimizing the overall impact on user convenience.
Data Source
AI summary
Embodiments are directed to optimizing the secure provisioning of credentials to mobile devices through use of risk decision non-overrides. In some embodiments, a service provider receives a request from a wallet provider to provision a credential associated with an account to a mobile device. The request includes a first risk level associated with the provisioning. The service provider receives a second risk level associated with the provisioning request from an issuer of the account. Based upon determining that a non-override condition exists, the service provider uses the first risk level from the wallet provider and accordingly causes a user authentication to occur. A non-override condition may be determined based upon scenario indicators received within the provisioning request. In some embodiments, the non-override condition may be ignored when the first risk level indicates medium risk and the second risk level indicates high risk.


