Secure Payment Credential Provisioning via Encrypted Unique Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The provisioning of payment credentials to mobile devices for contactless transactions is cumbersome and incurs undesirable wireless data usage charges, particularly due to the need for manual entry of user credentials and the involvement of over-the-air (OTA) provisioning processes.
Innovation Solution
A method and system for securely provisioning payment credentials to mobile devices using a remotely accessible server or a kiosk, which encrypts the credentials with a unique decryption key, allowing communication through a secure channel, and optionally storing the key or credentials in a secure element within the mobile device, thereby reducing the need for manual input and minimizing data usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual entry of user credentials is required for provisioning, then security is improved, but ease of operation deteriorates and time consumption increases
Solution Approach 1:
The system enables self-service provisioning by allowing the mobile device to automatically retrieve and store payment credentials without requiring manual user input. The device uses its existing identifier to autonomously complete the provisioning process, eliminating the need for users to manually enter credential information while maintaining security through the secure element.
Solution Approach 2:
A provisioning server acts as an intermediary between the credential storage instrument and the mobile device. The server receives the device identifier, retrieves the corresponding payment credentials, and automatically provisions them to the mobile device's secure element, eliminating the need for manual user input while ensuring secure credential delivery.
2Adaptability or versatility
If OTA provisioning process is used, then remote provisioning capability is improved, but data usage costs increase and time consumption increases
Solution Approach 1:
Payment credentials are pre-stored on credential storage instruments (such as SIM cards or secure elements) before the provisioning process. During provisioning, the system simply retrieves and transfers these pre-prepared credentials to the mobile device, eliminating the need for time-consuming manual entry or complex real-time credential generation over the air.
Solution Approach 2:
The provisioning server serves as an intermediary that facilitates rapid credential transfer by receiving the device identifier, looking up pre-prepared credentials in its database, and automatically provisioning them to the mobile device. This intermediary approach streamlines the remote provisioning process, reducing both time and data usage compared to traditional OTA methods.
3Adaptability or versatility
If multiple credential storage instruments are provisioned, then versatility is improved, but time consumption increases and complexity increases
Solution Approach 1:
The provisioning system is designed to handle multiple types of credential storage instruments (SIM cards, secure elements, external storage) through a universal interface. The mobile device can provision payment credentials from any supported credential storage instrument using the same automated process, enabling versatility without increasing user burden or time consumption.
Solution Approach 2:
The system automatically detects the type of credential storage instrument being used and adapts the provisioning process accordingly, without requiring user intervention. The device identifier is used to retrieve the appropriate credentials regardless of the source, enabling seamless provisioning of multiple credential types while maintaining efficiency.
4Reliability
If encryption with unique decryption key is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The provisioning server acts as a secure intermediary that handles the encryption and key management processes. The server encrypts payment credentials with unique decryption keys before provisioning them to the mobile device's secure element. This approach enhances security by ensuring that credentials are always encrypted and that decryption keys are securely managed, while the complexity of cryptographic operations is handled by the server rather than increasing the mobile device's complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and system for provisioning payment credentials usable by a mobile device in conducting a payment. The method is conducted at a provisioning system and comprises the steps of: receiving payment credentials from a receiving device, the payment credentials having been obtained from a portable payment device presented by a consumer at the receiving device; receiving, from the receiving device, an identifier entered by the consumer; identifying a mobile device or a secure element corresponding to the identifier; and communicating the payment credentials or a derivation of the payment credentials to the identified mobile device or the secure element to be securely stored in association with the mobile device. The method may include: encrypting the received payment credentials, the encrypted payment credentials having a unique decryption key; and wherein communicating a derivation of the payment credentials communicates the unique decryption key.