Risk-Based Mobile Credential Provisioning with Non-Override Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device credential provisioning lacks effective and secure processes to ensure that payment accounts are provisioned to rightful owners, as existing methods fail to adequately address risks of unauthorized provisioning and do not interrupt or delay the provisioning process.

Innovation Solution

A risk-based provisioning scheme that selectively chooses from multiple paths based on perceived risk levels, involving immediate provisioning for low risk, denial for high risk, and additional user authentication for medium risk, with the option to provision credentials in an inactive state and activate later, using a non-override condition to set risk levels and require additional authentication when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional authentication processes are implemented to verify rightful ownership, then security is improved, but provisioning time and process complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic risk-based authentication that adjusts the provisioning process based on assessed risk levels. Low-risk transactions proceed quickly with minimal authentication, while high-risk transactions trigger additional verification steps. This dynamic adaptation resolves the contradiction by making security measures proportional to actual risk rather than applying uniform authentication to all cases.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes authentication parameters (such as requiring additional verification methods or increasing verification stringency) based on risk level assessments. By parameterizing the authentication process rather than using a fixed approach, the system can intensify security measures only when necessary, thus maintaining speed for low-risk cases while ensuring security for high-risk cases.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple authentication channels are used to verify user identity, then authentication reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct channels (SMS, email, voice call, in-app) that can be independently selected based on risk level. Rather than implementing all authentication mechanisms simultaneously in the system, the solution divides authentication into modular components that are activated only when needed, reducing overall system complexity while maintaining high authentication reliability when required.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses communication channels as intermediaries to verify user identity without requiring complex direct authentication infrastructure. By leveraging existing communication channels (SMS providers, email servers, voice call systems) as intermediaries, the patent achieves high authentication reliability while avoiding the need to build and maintain complex proprietary authentication infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If credentials are provisioned in inactive state requiring later activation, then security is improved, but user convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary credential provisioning in an inactive state for high-risk cases, preparing the credentials in advance but keeping them dormant until activation. This preliminary action allows the system to pre-verify and prepare credentials securely, then activate them only after additional authentication confirms rightful ownership. The benefit is that the heavy security verification is done beforehand, and activation itself is a simple user action.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

For low-risk cases, the patent skips the intermediate inactive state entirely and provisions credentials directly to active status, rushing through the provisioning process without delay. This selective skipping ensures that users experiencing low-risk transactions enjoy immediate convenience, while only high-risk cases undergo the additional activation step, minimizing the overall impact on user convenience.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11574311B2Secure mobile device credential provisioning using risk decision non-overrides
Publication Date: 2023.02.07 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11574311B2 patent drawing
  • US11574311B2 patent drawing
  • US11574311B2 patent drawing

AI summary

Embodiments are directed to optimizing the secure provisioning of credentials to mobile devices through use of risk decision non-overrides. In some embodiments, a service provider receives a request from a wallet provider to provision a credential associated with an account to a mobile device. The request includes a first risk level associated with the provisioning. The service provider receives a second risk level associated with the provisioning request from an issuer of the account. Based upon determining that a non-override condition exists, the service provider uses the first risk level from the wallet provider and accordingly causes a user authentication to occur. A non-override condition may be determined based upon scenario indicators received within the provisioning request. In some embodiments, the non-override condition may be ignored when the first risk level indicates medium risk and the second risk level indicates high risk.