Multi-Scheme Credential Provisioning on NFC Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable electronic devices with NFC components face inefficiencies in selecting and using multiple available credentials for secure transactions, making it difficult to efficiently manage and utilize multiple secure credentials for contactless proximity-based communications.

Innovation Solution

The system provisions multiple credentials on an electronic device by using a transaction entity subsystem and an issuer subsystem to generate and store applets with associated link information, allowing for the selection and use of these credentials in transactions, enabling efficient management and utilization of multiple secure credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple credentials are provisioned on the electronic device, then the versatility and security of transactions are improved, but the device complexity and difficulty of credential management increase

Engineering Contradiction:
Improvecredential selection capabilityVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The credential data is segmented into distinct applets, each representing a separate credential. The system divides the credential provisioning process into discrete steps (receiving request data, identifying credentials, acquiring provisioning information, and provisioning individual applets). This segmentation allows multiple credentials to be managed as independent, manageable units rather than a monolithic structure, resolving the contradiction by making complexity manageable through structured division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential management system that acts as a mediator between the electronic device and multiple credentials. This intermediary layer handles the complexity of credential selection, activation, and switching automatically, allowing users to benefit from multiple credentials without directly managing the underlying complexity. The link information structure serves as an intermediary data structure that connects credentials to the device in a manageable way.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple credentials are stored on the secure element, then the security and functionality of contactless transactions are enhanced, but the provisioning process becomes more complex and time-consuming

Engineering Contradiction:
Improvetransaction securityVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-structuring the credential provisioning process with predefined applet templates and link information formats. Credential requests are processed through a standardized preliminary framework that identifies, acquires, and provisions credentials in a predetermined sequence. This preliminary structuring reduces the time required for each provisioning operation by eliminating ad-hoc decision-making during the actual provisioning execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs parameter changes by dynamically adjusting credential provisioning parameters such as applet identifiers, link information structures, and activation states. The system changes the state of credentials from inactive to active, and modifies provisioning parameters based on transaction requirements. This allows the system to efficiently manage multiple credentials by changing their operational parameters rather than recreating entire credential structures, thereby reducing provisioning time while maintaining security.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If link information is stored to associate applets, then the ease of credential switching is improved, but the data storage requirements and device complexity increase

Engineering Contradiction:
Improvecredential switching easeVSAvoiddata storage requirements
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential link information needed for credential association and switching, storing minimal necessary data (such as applet identifiers and association pointers) rather than complete credential datasets. The link information structure extracts and stores only the critical linking data required for fast credential switching, separating this from the actual credential secrets which remain secured in the secure element. This extraction approach enables easy credential switching while minimizing data storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10346848B2Provisioning multiple secure credentials on an electronic device
Publication Date: 2019.07.09 APPLE INC
  • US10346848B2 patent drawing
  • US10346848B2 patent drawing
  • US10346848B2 patent drawing

AI summary

Systems, methods, and computer-readable media for provisioning multiple credentials of a multi-scheme card on an electronic device for selective use in a secure transaction are provided.