Multi-Scheme Credential Provisioning on NFC Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Portable electronic devices with NFC components face inefficiencies in selecting and using multiple available credentials for secure transactions, making it difficult to efficiently manage and utilize multiple secure credentials for contactless proximity-based communications.
Innovation Solution
The system provisions multiple credentials on an electronic device by using a transaction entity subsystem and an issuer subsystem to generate and store applets with associated link information, allowing for the selection and use of these credentials in transactions, enabling efficient management and utilization of multiple secure credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple credentials are provisioned on the electronic device, then the versatility and security of transactions are improved, but the device complexity and difficulty of credential management increase
Solution Approach 1:
The credential data is segmented into distinct applets, each representing a separate credential. The system divides the credential provisioning process into discrete steps (receiving request data, identifying credentials, acquiring provisioning information, and provisioning individual applets). This segmentation allows multiple credentials to be managed as independent, manageable units rather than a monolithic structure, resolving the contradiction by making complexity manageable through structured division.
Solution Approach 2:
The patent introduces an intermediary credential management system that acts as a mediator between the electronic device and multiple credentials. This intermediary layer handles the complexity of credential selection, activation, and switching automatically, allowing users to benefit from multiple credentials without directly managing the underlying complexity. The link information structure serves as an intermediary data structure that connects credentials to the device in a manageable way.
2Reliability
If multiple credentials are stored on the secure element, then the security and functionality of contactless transactions are enhanced, but the provisioning process becomes more complex and time-consuming
Solution Approach 1:
The system performs preliminary actions by pre-structuring the credential provisioning process with predefined applet templates and link information formats. Credential requests are processed through a standardized preliminary framework that identifies, acquires, and provisions credentials in a predetermined sequence. This preliminary structuring reduces the time required for each provisioning operation by eliminating ad-hoc decision-making during the actual provisioning execution.
Solution Approach 2:
The patent employs parameter changes by dynamically adjusting credential provisioning parameters such as applet identifiers, link information structures, and activation states. The system changes the state of credentials from inactive to active, and modifies provisioning parameters based on transaction requirements. This allows the system to efficiently manage multiple credentials by changing their operational parameters rather than recreating entire credential structures, thereby reducing provisioning time while maintaining security.
3Ease of operation
If link information is stored to associate applets, then the ease of credential switching is improved, but the data storage requirements and device complexity increase
Solution Approach 1:
The patent extracts only the essential link information needed for credential association and switching, storing minimal necessary data (such as applet identifiers and association pointers) rather than complete credential datasets. The link information structure extracts and stores only the critical linking data required for fast credential switching, separating this from the actual credential secrets which remain secured in the secure element. This extraction approach enables easy credential switching while minimizing data storage requirements.
Data Source
AI summary
Systems, methods, and computer-readable media for provisioning multiple credentials of a multi-scheme card on an electronic device for selective use in a secure transaction are provided.


