Payment Instrument Provisioning Authentication With Secure Data Entry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment instrument provisioning methods are vulnerable to unauthorized users provisioning payment instruments without the knowledge or consent of the authorized user, particularly through social engineering techniques, leading to potential fraud.

Innovation Solution

A method and system for authenticating payment instrument provisioning that involves secure data entry devices, electronic devices, and servers to verify the authenticity of the user by matching secure data, generating authorization messages, and approving or declining the provisioning request based on validation success.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual entry of payment instrument information is allowed during provisioning, then ease of operation is improved, but security deteriorates due to vulnerability to unauthorized provisioning

Engineering Contradiction:
Improveease of provisioningVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A secure data entry device is introduced as an intermediary between the user and the provisioning system. This device captures payment instrument information through its interface (card reader, camera, or manual entry) and securely transmits it to the server, eliminating the need for users to manually enter sensitive information on their electronic devices. The intermediary device provides a secure environment for data capture and transmission, resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If identity verification is implemented during provisioning, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure data entry device serves as an intermediary that handles all identity verification and validation processes. The device captures secure data, validates it against stored information, and only transmits authenticated information to the server. This concentrates the complexity in a dedicated security device rather than distributing it throughout the entire provisioning system, achieving security enhancement while managing complexity through specialized hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If secure data verification is performed during provisioning, then fraud prevention is improved, but provisioning time increases

Engineering Contradiction:
Improvefraud preventionVSAvoidprovisioning time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The secure data entry device performs verification of payment instrument information and user identity before the provisioning process is initiated. By conducting security checks in advance and only transmitting verified information to the server, the system prevents fraudulent provisioning attempts early in the process. This preliminary validation approach reduces the overall time required compared to performing multiple verification steps during and after provisioning.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12361420B2Systems and methods for provisioning a payment instrument
Publication Date: 2025.07.15 WORLDPAY LTD
  • US12361420B2 patent drawing
  • US12361420B2 patent drawing
  • US12361420B2 patent drawing

AI summary

The invention relates generally to the provisioning of payment instruments onto electronic devices such as a mobile telephone, tablet, laptop or wearable, and in particular to securely provisioning payment instrument for which authorisation for the provisioning must be provided by a payment instrument issuer. A first embodiment is provided in which data that is generated during module a transaction is received by an electronic device and transmitted controller from the electronic device to a server associated with an acquirer. The data received from the electronic device is compared to the data generated during the transaction and, if these match, provisioning is authorised. A second embodiment is provided in which a server associated with an acquirer generates an identification message that is separate from but based on a response message associated with a transaction, and provisioning is authorised or declined based on the identification message.