Frictionless Credential Provisioning via Ownership Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for provisioning native payment credentials on electronic devices are inefficient, requiring users to provide proof of ownership and navigate through challenges, leading to a cumbersome process.
Innovation Solution
The system employs an administration entity (AE) subsystem to facilitate frictionless credential provisioning by using ownership tokens. These tokens are generated and stored in a user's AE locker, allowing for seamless authentication and provisioning across devices without the need for additional proof of ownership.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional credential provisioning methods are used, then security verification is maintained, but the provisioning process becomes cumbersome and inefficient
Solution Approach 1:
The system performs preliminary actions by pre-establishing device trust relationships with the administration entity and pre-generating ownership tokens before the actual credential provisioning is needed. When a user authenticates their device to the administration entity, the system automatically stores an ownership token in the device's secure enclave, enabling frictionless future provisioning without requiring repeated manual verification.
Solution Approach 2:
The patent introduces an intermediary mechanism using ownership tokens that mediate between the user's authentication state and the credential provisioning process. These tokens act as cryptographic intermediaries that carry the user's authorization information, allowing the system to automatically provision credentials without direct manual intervention or repeated security challenges.
2Reliability
If additional proof of ownership verification is required, then security is enhanced, but the provisioning process becomes more complex and time-consuming
Solution Approach 1:
The system performs the security verification action in advance during device authentication. When a user authenticates their device to the administration entity, the system automatically stores an ownership token in the device's secure enclave. This preliminary security establishment eliminates the need for repeated manual verification during subsequent credential provisioning, reducing both time and maintaining security.
Solution Approach 2:
The patent creates a cryptographic copy of the user's authorization state in the form of an ownership token stored in the device's secure enclave. This token is a self-contained representation of the user's authenticated state, allowing the system to verify authorization quickly without requiring the user to re-provide authentication credentials or engage in additional verification challenges.
3Ease of operation
If manual credential provisioning steps are reduced, then user convenience is improved, but the system complexity increases
Solution Approach 1:
The system implements self-service by automatically handling the credential provisioning process once the user authenticates their device. The administration entity automatically generates and stores ownership tokens in the device's secure enclave, and automatically provisions credentials when triggered. This eliminates manual provisioning steps while the system manages the complexity of token generation, storage, and credential delivery.
Solution Approach 2:
The ownership token serves as an intermediary that simplifies the user experience by automatically carrying authorization information throughout the provisioning process. For the user, this means simply authenticating their device once, and the system handles all subsequent complexity of token management, credential generation, and delivery without requiring user intervention or understanding of the underlying system complexity.
Data Source
AI summary
Systems, methods, and computer-readable media for facilitating frictionless credential provisioning on a user computing device are provided. Special “frictionless tokens” (e.g., ownership tokens) may be generated for each existing credential in a user's digital wallet. Such tokens may be stored in a user's AE locker (e.g., iCloud keychain) and synchronized across the user's devices using any suitable security features (e.g., using any suitable secure enclave processor (“SEP”)-based encryption). Such a token, as may be stored in a device's SEP, may be configured only to be read on that physical device. In this manner, the user may no longer need provide further proof of ownership of a credential or be hassled by passing any other challenge, but, instead, the additional security may be achieved using the ownership token, which may use the user's AE or device passcode in association with the user's physical device (and its SEP).


