Mobile Device NFC Provisioning for Secure Transaction Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile communication systems lack efficient methods for securely provisioning mobile devices to perform transactions without the need for physical security tokens, leading to inconvenience and increased costs for financial institutions.
Innovation Solution
A mobile communications device and method that utilizes near field communication (NFC) to receive authentication data from a security token, allowing the device to be provisioned for secure transactions, such as payments or access control, using existing account information, thereby eliminating the need to carry physical tokens and reducing the need for new account issuances.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical security tokens are used for mobile device provisioning, then secure transaction authentication is achieved, but user convenience deteriorates and financial institution costs increase
Solution Approach 1:
The patent creates a digital copy of the security token's authentication capability within the mobile device's secure element. The provisioning server generates a digital representation of the token's cryptographic functions that resides in the mobile device, allowing the device to authenticate transactions without requiring the physical token. This copying approach maintains security while eliminating the need to carry physical tokens.
Solution Approach 2:
The patent replaces the mechanical/physical security token system with an electronic/digital authentication system. Instead of using a physical card or token that must be manually presented, the system uses electronic cryptographic operations within the mobile device's secure element to perform authentication. This substitution eliminates physical handling while maintaining security through cryptographic verification.
2Reliability
If physical security tokens are used for mobile device provisioning, then secure transaction authentication is achieved, but costs for financial institutions increase
Solution Approach 1:
The patent performs provisioning actions in advance through automated enrollment processes. The mobile device is pre-configured with authentication credentials through secure communication with the provisioning server before transactions occur. This preliminary setup eliminates the need for physical token distribution and manual account provisioning, reducing operational costs while maintaining security.
Solution Approach 2:
The patent enables self-service provisioning where the mobile device automatically enrolls itself with the provisioning server without requiring manual intervention from financial institution staff. The device initiates the provisioning process, and the server automatically generates and delivers credentials, eliminating labor costs associated with manual token distribution and account creation.
3Adaptability or versatility
If new accounts are issued for mobile transactions, then transaction capability is provided, but the number of accounts increases and costs increase
Solution Approach 1:
The patent makes existing accounts multi-functional by enabling them to work across both physical token systems and mobile device systems. The same account credentials can be used for traditional token-based transactions and mobile-based transactions, eliminating the need to create separate accounts for mobile functionality. This universal approach reduces account proliferation while maintaining full transaction capability.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables secure and convenient transaction provisioning on mobile devices, reducing the necessity for physical security tokens and minimizing the issuance of new accounts, thus saving costs and enhancing user convenience.
Implementation Method 1
NFC technology is commonly used for contactless short-range communications based on radio frequency identification (RFID) standards, using magnetic field induction to enable communication between electronic devices
Data Source
AI summary
A mobile communications device may include a memory, a transceiver, and a controller coupled with the memory and the transceiver. The controller may be capable of receiving first authentication data from a security token via communication with the security token, where the first authentication data is associated with an account. The controller may also be capable of transmitting the first authentication data via the transceiver, and receiving second authentication data via the transceiver, where the second authentication data is also associated with the account. The controller may be further capable of storing the second authentication data in the memory, and transmitting a transaction request using the second authentication data.


